C&CMembers
C&C

BazLoader, Amadey, and StealC V2 Chain Targets Algeria and Italy via Single German /24

A 170 KB dropper identified as BazLoader/egairtigado initiates a three-stage loader chain that deploys Amadey and then stages StealC V2 credential harvesting, with all C2 traffic routed to two IP addresses inside a single /24 subnet under AS214351 in Germany. The campaign carries an espionage motivation tag and is associated with the WoodyRAT malware family, with regional targeting logged against Algeria and Italy. A self-signed 'PureCrack' TLS certificate valid until 2036 and raw-IP HTTP beaconing that bypasses DNS entirely define the operational signature.

Jun 13, 2026, 14:47 (UTC+9)Last seenJun 22, 2026Severity100ByCTX TeamIOC37MITRE62RegionsDZIT

A 170-kilobyte PE32 dropper first submitted to public scanning infrastructure on 12 June 2026 is the entry point for one of the more operationally compact espionage-oriented loader chains CTX Team has tracked this quarter. The binary — identified as BazLoader/egairtigado and observed in the wild as sprd2.exe — touches down in the user Temp directory, copies itself to C:\Windows\8amu8dw.exe, and immediately begins beaconing over raw IPv4 HTTP to a pair of hosts consolidated within the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence