
One Reflective Loader, Three Antivirus Verdicts: A Single Kit Unmasked
Three Windows binaries that antivirus engines classify as separate crimeware families — Stealc, a clipbanker, and a bank trojan — all trip the exact same reflective-loader YARA rules underneath. CTX Team's review of an 11-file cluster tied to early-July 2026 C2 infrastructure finds that shared code, not shared labels, is what actually connects the payloads.
Antivirus engines looked at three Windows binaries and returned three different answers: stealc/marte, clipbanker/tedy, mikey/bank. A closer read of the code underneath tells a different story. All three — a 10.5MB file masquerading as "EmailCheckerPro 2.0.exe", a 253KB "WindowsHost.exe," and a 333KB dropper staged under %APPDATA% — co-fire the same two YARA rules, ReflectiveLoader and INDICATOR_SUSPICIOUS_ReflectiveLoader, tripwires that flag reflective DLL injection artifacts rather than any…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read