C&CMembers
C&C

Phorpiex Clipbanker Uses Six Greek-Letter C2 Endpoints to Steal Crypto

A 103-kilobyte Windows trojan named wescgsvcs.exe beacons to a single Spamhaus DROP-listed server exposing six Greek-alphabetically ordered HTTP endpoints, pointing to a structured tasking API. The binary combines clipboard hijacking for cryptocurrency theft with layered sandbox evasion, a fifteen-year timestomped PE header, and registry-based persistence.

Jun 18, 2026, 20:06 (UTC+9)Last seenJun 18, 2026Severity100ByCTX TeamIOC12MITRE31

A 103-kilobyte Windows executable named wescgsvcs.exe — crafted to blend visually with legitimate Windows service binaries — has been quietly draining cryptocurrency wallets through one of the more methodical evasion stacks CTX Team has documented in this family class. The binary, confirmed as a Phorpiex/Fragtor trojan with a clipbanker payload, beacons to a single command-and-control server at 185.215.113.84 that exposes exactly six HTTP endpoints named in Greek alphabetical order: alpha,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence