
Shared Beacon String Links Clipbankers, a Stealer, and a Rogue Driver
A signed-but-expired Windows driver, a CMSTP UAC-bypass rule, and a recycled XOR-obfuscated beacon string tie together seventeen nominally unrelated malware samples. The pattern points to one production pipeline behind clipboard hijackers, a credential stealer, a binder, and a BYOVD disabler, all funnelling into three IPs on a single German autonomous system.
Three separate rule-level fingerprints, not a single named family, are what make this cluster worth a second look. A signed-but-expired Windows driver built to terminate security processes fires Elastic's "Windows_VulnDriver_ProcessMonitorDriver" detection on one sample; a UAC-bypass rule tied to the CMSTP COM interface [T1218.003] co-fires on two nominally unrelated loaders; and a Florian Roth YARA signature for a single-byte XOR-obfuscated "Mozilla/5.0" string turns up in three files that…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read