
Shared Loader Code Links Five 'Unrelated' Malware Families to One C2
A clipbanker and a bazarloader sample — flagged by AV engines as entirely separate threats — both trip the same reflective-DLL-injection YARA rules, exposing a shared builder or code-sharing arrangement beneath unrelated family labels. The finding anchors a wider cluster of ten files converging on identical bare-IP C2 infrastructure.
Ten files, five different antivirus family labels, and one code-level fingerprint that should not be there. A clipboard-hijacking banker compiled as a 251KB Windows executable and a bazaar-style loader shipped as a 109KB DLL — tools that vendor engines classify as entirely separate malware — both fire the identical YARA rule pair `INDICATOR_SUSPICIOUS_ReflectiveLoader and ReflectiveLoader.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read