C&CMembers
C&C

One Reflective Loader, Three Antivirus Verdicts: A Single Kit Unmasked

Three Windows binaries that antivirus engines classify as separate crimeware families — Stealc, a clipbanker, and a bank trojan — all trip the exact same reflective-loader YARA rules underneath. CTX Team's review of an 11-file cluster tied to early-July 2026 C2 infrastructure finds that shared code, not shared labels, is what actually connects the payloads.

Jul 8, 2026, 18:49 (UTC+9)Last seenJul 8, 2026Severity100ByCTX TeamIOC25MITRE20RegionsHK

Antivirus engines looked at three Windows binaries and returned three different answers: stealc/marte, clipbanker/tedy, mikey/bank. A closer read of the code underneath tells a different story. All three — a 10.5MB file masquerading as "EmailCheckerPro 2.0.exe", a 253KB "WindowsHost.exe," and a 333KB dropper staged under %APPDATA% — co-fire the same two YARA rules, ReflectiveLoader and INDICATOR_SUSPICIOUS_ReflectiveLoader, tripwires that flag reflective DLL injection artifacts rather than any…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence