C&CMembers
C&C

Five Malware Families, One Shared Diamotrix C2 Panel

Eight new samples spanning ClipBanker, StealC v2, PowerLoader, and a Rhadamanthys/Formbook-flagged file all trace back to the same reflective-loader stub and the same '/diamo/data.php' backend documented in prior coverage. Static threat labels suggest five unrelated infections; rule matches and infrastructure say otherwise.

Jul 8, 2026, 02:44 (UTC+9)Last seenJul 8, 2026Severity100ByCTX TeamIOC20MITRE48RegionsES

Eight new binaries entered the same tracked cluster this week, and on paper they look like five unrelated infections: a ClipBanker variant, a second ClipBanker variant, a third ClipBanker variant, a StealC-labelled stealer, a PowerLoader-tagged loader, and a file flagged as Rhadamanthys whose only sandbox verdict instead calls it Formbook. Static antivirus labels alone would read this as a grab-bag of commodity crimeware.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence