APTMembers
APT

WHQL-Signed Kernel Driver With 2/76 Detections Opens Stealc v2 Kill Chain

A 34 KB Windows kernel driver bearing a Microsoft WHQL certificate chain achieves only 2 of 76 detections on VirusTotal, serving as the opening move in a five-stage campaign that delivers Stealc v2 credential stealers and clipboard hijackers targeting cryptocurrency wallets. The driver, masquerading as a Safetica process-monitor component, neutralises endpoint defences before a single payload executes, enabling a layered financial-theft stack that bypasses Chromium app-bound encryption.

Jun 13, 2026, 02:32 (UTC+9)Last seenJun 13, 2026Severity100ByCTX TeamActorWizard SpiderGrim SpiderIOC20MITRE71RegionsARDEINNGRO

A 34-kilobyte Windows kernel driver signed by the Microsoft Windows Hardware Compatibility Publisher — carrying a WHQL certificate chain that traces back to Microsoft's own root authority — is being deployed as the opening move in a five-stage financial-theft campaign that ultimately delivers Stealc v2 credential stealers capable of bypassing Chromium app-bound encryption and in-process clipboard hijackers targeting cryptocurrency wallet addresses.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence