APTMembers
APT

Stealer Hosting Cluster Grows: Two New IPs, Panels Span Two Providers

Two new IPs have joined a five-node AS214351 cluster tied to Femo IT Solutions, extending a rotating, brand-impersonating TLS certificate pattern first seen in earlier StealC v2 reporting. Eight new payload files spanning RedLine, StealC v2, Amadey and Carberp-lineage clipboard hijackers now ride the same infrastructure, with identical PHP panel paths appearing on a second, unrelated ASN.

Jul 6, 2026, 18:48 (UTC+9)Last seenJul 6, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC30MITRE28RegionsJO

Two IP addresses — 196.251.107.104 and 196.251.107.130 — have just joined a five-node hosting cluster sitting on AS214351, registered to Femo IT Solutions Limited, a UK-listed shell address at 71-75 Shelton Street in London's Covent Garden. Both are new since CTX Team's earlier coverage of a StealC v2 campaign built around Chrome credential-store bypass tooling.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence