C&CMembers
C&C

Wizard Spider Cluster Adds CMSTP Bypass as Loader Cohort Hits Five

New indicators tied to this cluster don't touch the C2 infrastructure but thicken the payload layer with a second, independent evasion toolset — two unrelated binaries trip a ditekSHen YARA rule for CMSTP-based UAC bypass. Neither sample belongs to the shared-imphash loader family that anchors the rest of the set, pointing to at least two separately sourced toolchains running side by side.

Sep 30, 2026, 06:30 (UTC+9)Last seenSep 30, 2026Severity100ByCTX TeamActorWizard SpiderGrim SpiderIOC39MITRE59RegionsBEVN

The freshest wave of indicators tied to this cluster doesn't expand the target list or spin up new command posts — it thickens the payload layer with a defense-evasion technique that wasn't visible in the earlier build. Two newly logged samples that share no import-table hash, no signer, and no vendor label between them — a file flagged as trojan.filerepmalware/misc (338458ce…) and one carrying a "Curiositystream by D3v.exe" filename and tagged trojan.cymulate (60b1267c…) — both trip the same…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence