C&CMembers
C&C

Five-Family Infostealer Campaign Bypasses Chrome 127 Encryption via Single Rogue AS

A campaign chaining Amadey, StealC v2, and three clipboard-hijacking variants routes all C2 traffic through AS214351, a single autonomous system stood up in October 2024. Its StealC v2 payload fires a YARA rule confirming active capability to defeat the app-bound encryption Chrome 127 introduced to block credential theft.

Jun 6, 2026, 07:32 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamIOC53RegionsBR

A multi-stage infostealer and clipboard-hijacking campaign deploying at least five distinct malware families — Amadey, StealC v2, two statically linked ClipBanker variants, and a purpose-built custom dropper — has been routing all of its command-and-control traffic exclusively through AS214351, a single autonomous system operated by Femo It Solutions Limited that was created in October 2024 and spans address space registered under two separate regional internet registries.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence