C&CMembers
C&C

Seven Malware Family Labels Turn Out to Be One StealC Codebase

Eleven files tied to a single command-and-control cluster were tagged by vendors as seven separate families — StealC v2, TinyNuke, PowerLoader, Carberp, Vidar, RedLine and MaskGramStealer. Shared YARA rules, IDS C2 signatures, and a two-node AS214351 hosting fingerprint suggest one builder repackaging a single stealer behind crypto-themed lures.

Aug 13, 2026, 06:28 (UTC+9)Last seenAug 13, 2026Severity100ByCTX TeamIOC27MITRE45RegionsPKUS

Eleven files sitting behind a single command-and-control cluster were flagged by vendor engines as seven different malware families — StealC v2, TinyNuke, PowerLoader, Carberp, Vidar, RedLine and a Telegram-adjacent stealer tracked as MaskGramStealer. Six independent YARA rulesets and a run of IDS signatures tell a different story: several of these "families" are the same codebase and the same command-and-control protocol, wrapped in different crypto-themed lure names and shipped through…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence