C&CMembers
C&C

Two Unrelated Trojans Share One Crypter's XOR Fingerprint

A CMSTP-based UAC-bypass stealer and an lsass.exe-masquerading dropper carry different VirusTotal labels and mismatched imphashes, yet both trip the same Mozilla/5.0 XOR-obfuscation rule and share a compile timestamp. The overlap points to a shared crypter or builder stage, not a shared malware family.

Jul 3, 2026, 11:48 (UTC+9)Last seenAug 31, 2026Severity100ByCTX TeamActorTA428ThunderCatsIOC11MITRE30RegionsCHJO

Two brand-new payloads dropped into this snapshot's file cohort are not, on paper, the same malware. VirusTotal's own labels split them cleanly — one reads trojan.stealer/bypassuac, the other trojan.phil/mint — and neither carries a matching imphash. Yet a UAC-bypass stealer identified by the crowdsourced YARA rule INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM (8cf4ae00be0fe987cc14ae74b0b64c188083b8bbe3b7397239cefd594492c6cd) and a second binary masquerading as core Windows processes both fire a…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence