
Stealc v2, ClipBanker, AgentB Hit Crypto Wallets via Single Rogue ASN
A financially motivated campaign active through May–June 2026 chained three commodity malware families against shared command-and-control infrastructure, exfiltrating complete Exodus cryptocurrency wallet secrets from at least one confirmed victim. Every payload in the set strips its PE import table and beacons via raw IP address, a uniform build discipline that kept portions of the toolset undetected at collection time.
A financially motivated campaign active through May and June 2026 has deployed three functionally distinct malware families — Stealc v2, a ClipBanker, and an AgentB-family trojan — against the same command-and-control infrastructure, producing confirmed victim artefacts that include four encrypted Exodus cryptocurrency wallet files and a FileZilla FTP credential store.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read