
BazLoader, Amadey, and StealC V2 Chain Targets Algeria and Italy via Single German /24
A 170 KB dropper identified as BazLoader/egairtigado initiates a three-stage loader chain that deploys Amadey and then stages StealC V2 credential harvesting, with all C2 traffic routed to two IP addresses inside a single /24 subnet under AS214351 in Germany. The campaign carries an espionage motivation tag and is associated with the WoodyRAT malware family, with regional targeting logged against Algeria and Italy. A self-signed 'PureCrack' TLS certificate valid until 2036 and raw-IP HTTP beaconing that bypasses DNS entirely define the operational signature.
A 170-kilobyte PE32 dropper first submitted to public scanning infrastructure on 12 June 2026 is the entry point for one of the more operationally compact espionage-oriented loader chains CTX Team has tracked this quarter. The binary — identified as BazLoader/egairtigado and observed in the wild as sprd2.exe — touches down in the user Temp directory, copies itself to C:\Windows\8amu8dw.exe, and immediately begins beaconing over raw IPv4 HTTP to a pair of hosts consolidated within the…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read