
Stealer Hosting Cluster Grows: Two New IPs, Panels Span Two Providers
Two new IPs have joined a five-node AS214351 cluster tied to Femo IT Solutions, extending a rotating, brand-impersonating TLS certificate pattern first seen in earlier StealC v2 reporting. Eight new payload files spanning RedLine, StealC v2, Amadey and Carberp-lineage clipboard hijackers now ride the same infrastructure, with identical PHP panel paths appearing on a second, unrelated ASN.
Two IP addresses — 196.251.107.104 and 196.251.107.130 — have just joined a five-node hosting cluster sitting on AS214351, registered to Femo IT Solutions Limited, a UK-listed shell address at 71-75 Shelton Street in London's Covent Garden. Both are new since CTX Team's earlier coverage of a StealC v2 campaign built around Chrome credential-store bypass tooling.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read