SVCStealer is a Python-based information stealer first documented in May 2023 by Cyble Research Labs, categorized as a credential-stealing malware that primarily targets browser-stored data, cryptocurrency wallets, and session tokens. The malware is operated by an unknown threat actor and is distributed via phishing campaigns, often disguised as game cheats or software cracks.
SVCStealer propagates through spear-phishing emails containing malicious Microsoft Office documents or archive files that drop the Python loader onto the victim's machine, as detailed in Cyble's June 2023 report. The malware establishes command-and-control (C2) communication over HTTP POST requests to a Telegram bot API, using Telegram as the exfiltration channel for stolen data, corresponding to MITRE ATT&CK technique T1071 (Application Layer Protocol). Persistence is achieved via a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value name WindowsUpdateService, mapping to T1547 (Boot or Logon Autostart Execution). Evasion techniques include obfuscation using base64-encoded strings, anti-debugging checks that detect debuggers like WinDbg via T1055 (Process Injection), and sandbox evasion by checking system uptime and VM artifacts. The stealer collects credentials from Chromium-based browsers (Chrome, Edge, Brave) and Firefox, extracts cookies and autofill data, and targets cryptocurrency wallets such as Exodus, Atomic, and Electrum by enumerating file system paths associated with T1083 (File and Directory Discovery).
First observed in the wild in April 2023, SVCStealer was initially reported by Cyble in a May 2023 threat advisory, with subsequent campaigns in July and November 2023 targeting gaming communities on Discord and Steam. No high-profile corporate victims have been publicly named, and the malware does not exploit any specific CVEs, relying instead on social engineering and document macros for initial access. Law enforcement actions have not been documented as of early 2024.
Known file hashes include the SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 from a sample on MalwareBazaar; behavioral signatures include the creation of a mutex named GlobalSVCStealer_Mutex and outbound connections to api.telegram.org on port 443. Registry artifacts include the persistence key HKCU...RunWindowsUpdateService pointing to a Python executable, and a User-Agent string of python-requests/2.28.1 is commonly observed in network traffic.
SVCStealer causes significant data exfiltration, leading to account takeovers of email, social media, and gaming platforms, as well as financial losses from stolen cryptocurrency wallet keys. The primary affected sectors are individual users and small-to-medium enterprises in the gaming and esports industries, with estimated losses per incident ranging from a few hundred to several thousand dollars due to credential resale on dark web marketplaces.
Defenders should deploy endpoint detection and response (EDR) solutions like SentinelOne or CrowdStrike with behavioral rules that flag Python execution from non-standard directories and block outbound connections to Telegram endpoints on corporate networks. Organizations should also implement email filtering to block macro-laden documents and enforce application whitelisting using tools such as Microsoft Defender for Endpoint, referencing the MDE query for DeviceEvents where ActionType is ProcessCreated with FileName containing python.exe.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.