C&CMembers
C&C

Shared Loader Code Links Five 'Unrelated' Malware Families to One C2

A clipbanker and a bazarloader sample — flagged by AV engines as entirely separate threats — both trip the same reflective-DLL-injection YARA rules, exposing a shared builder or code-sharing arrangement beneath unrelated family labels. The finding anchors a wider cluster of ten files converging on identical bare-IP C2 infrastructure.

Sep 10, 2026, 06:48 (UTC+9)Last seenSep 10, 2026Severity100ByCTX TeamIOC21MITRE48

Ten files, five different antivirus family labels, and one code-level fingerprint that should not be there. A clipboard-hijacking banker compiled as a 251KB Windows executable and a bazaar-style loader shipped as a 109KB DLL — tools that vendor engines classify as entirely separate malware — both fire the identical YARA rule pair `INDICATOR_SUSPICIOUS_ReflectiveLoader and ReflectiveLoader.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence