C&CMembers
C&C

Cheat-Tool Loader Feeds a Stolen-Credential Log Shop via Dual-ASN C2

A C2 backend built around diamotrix.world runs the identical /diamo/post.php panel across two unrelated hosting providers in France and Germany, fed by a PEiD-packed loader distributed as 'B3RAP Leecher v2.exe.' Alongside it sit six plaintext files whose paths spell out Exodus wallet seeds, 2FA secrets, Telegram sessions, and FileZilla credentials, all wrapped in matching 'KidnapperCloud' archive branding.

Aug 15, 2026, 07:41 (UTC+9)Last seenAug 22, 2026Severity100ByCTX TeamIOC57MITRE61RegionsUS

A command-and-control backend built around the domain diamotrix.world is running the same check-in panel — the path /diamo/post.php — across two IP addresses sitting on entirely unrelated hosting providers, one in France and one in Germany. Feeding that backend is a PEiD-packed .NET loader distributed under the branding "B3RAP Leecher v2.exe," a tool marketed into gaming and combo-list communities rather than built for a targeted intrusion.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence