
Seven Malware Family Labels Turn Out to Be One StealC Codebase
Eleven files tied to a single command-and-control cluster were tagged by vendors as seven separate families — StealC v2, TinyNuke, PowerLoader, Carberp, Vidar, RedLine and MaskGramStealer. Shared YARA rules, IDS C2 signatures, and a two-node AS214351 hosting fingerprint suggest one builder repackaging a single stealer behind crypto-themed lures.
Eleven files sitting behind a single command-and-control cluster were flagged by vendor engines as seven different malware families — StealC v2, TinyNuke, PowerLoader, Carberp, Vidar, RedLine and a Telegram-adjacent stealer tracked as MaskGramStealer. Six independent YARA rulesets and a run of IDS signatures tell a different story: several of these "families" are the same codebase and the same command-and-control protocol, wrapped in different crypto-themed lure names and shipped through…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read