C&CMembers
C&C

Stealc v2, ClipBanker, AgentB Hit Crypto Wallets via Single Rogue ASN

A financially motivated campaign active through May–June 2026 chained three commodity malware families against shared command-and-control infrastructure, exfiltrating complete Exodus cryptocurrency wallet secrets from at least one confirmed victim. Every payload in the set strips its PE import table and beacons via raw IP address, a uniform build discipline that kept portions of the toolset undetected at collection time.

Jun 3, 2026, 23:52 (UTC+9)Last seenJun 3, 2026Severity100ByCTX TeamIOC37MITRE43RegionsRS

A financially motivated campaign active through May and June 2026 has deployed three functionally distinct malware families — Stealc v2, a ClipBanker, and an AgentB-family trojan — against the same command-and-control infrastructure, producing confirmed victim artefacts that include four encrypted Exodus cryptocurrency wallet files and a FileZilla FTP credential store.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence