
Five Malware Families, One Shared Diamotrix C2 Panel
Eight new samples spanning ClipBanker, StealC v2, PowerLoader, and a Rhadamanthys/Formbook-flagged file all trace back to the same reflective-loader stub and the same '/diamo/data.php' backend documented in prior coverage. Static threat labels suggest five unrelated infections; rule matches and infrastructure say otherwise.
Eight new binaries entered the same tracked cluster this week, and on paper they look like five unrelated infections: a ClipBanker variant, a second ClipBanker variant, a third ClipBanker variant, a StealC-labelled stealer, a PowerLoader-tagged loader, and a file flagged as Rhadamanthys whose only sandbox verdict instead calls it Formbook. Static antivirus labels alone would read this as a grab-bag of commodity crimeware.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read