
Wizard Spider Cluster Adds CMSTP Bypass as Loader Cohort Hits Five
New indicators tied to this cluster don't touch the C2 infrastructure but thicken the payload layer with a second, independent evasion toolset — two unrelated binaries trip a ditekSHen YARA rule for CMSTP-based UAC bypass. Neither sample belongs to the shared-imphash loader family that anchors the rest of the set, pointing to at least two separately sourced toolchains running side by side.
The freshest wave of indicators tied to this cluster doesn't expand the target list or spin up new command posts — it thickens the payload layer with a defense-evasion technique that wasn't visible in the earlier build. Two newly logged samples that share no import-table hash, no signer, and no vendor label between them — a file flagged as trojan.filerepmalware/misc (338458ce…) and one carrying a "Curiositystream by D3v.exe" filename and tagged trojan.cymulate (60b1267c…) — both trip the same…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read