C&CMembers
C&C

Nine Payloads, One Escape Hatch: Callbacks Skip the DNS Layer

A five-day delivery wave of nine Windows binaries — an Amadey loader, a Stealc v2 stealer, and two ClipBanker variants — all phone home to bare IP addresses instead of domains. Three differently-labelled samples trip the identical direct-IP-callback signature, pointing to one shared pipeline rather than three coincidental infections.

Jul 1, 2026, 14:51 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC13MITRE21RegionsKW

A delivery wave of nine Windows binaries surfaced within a five-day window in June, and every payload built around it — a downloader, an infostealer, and two clipboard hijackers — makes the same operational choice: none of them resolve a domain to reach their controller. The IDS signature "POLICY-OTHER HTTP request by IPv4 address attempt" fires identically on three differently labelled samples — de05caad…87ec0 (flagged trojan.amadey/lumma), e78c9ae…8a41f93 (trojan.stealc/bazloader) and…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence