
Cheat-Tool Loader Feeds a Stolen-Credential Log Shop via Dual-ASN C2
A C2 backend built around diamotrix.world runs the identical /diamo/post.php panel across two unrelated hosting providers in France and Germany, fed by a PEiD-packed loader distributed as 'B3RAP Leecher v2.exe.' Alongside it sit six plaintext files whose paths spell out Exodus wallet seeds, 2FA secrets, Telegram sessions, and FileZilla credentials, all wrapped in matching 'KidnapperCloud' archive branding.
A command-and-control backend built around the domain diamotrix.world is running the same check-in panel — the path /diamo/post.php — across two IP addresses sitting on entirely unrelated hosting providers, one in France and one in Germany. Feeding that backend is a PEiD-packed .NET loader distributed under the branding "B3RAP Leecher v2.exe," a tool marketed into gaming and combo-list communities rather than built for a targeted intrusion.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read