
Shared Panel Path Ties Five Rebranded Stealers to One C2 Backend
Eleven Windows payloads carrying five different VirusTotal labels — Amadey/Lumma, Stealc, ClipBanker/Cerbu, Kasidet/Fragtor, and Barys — all check in with the same small IP cluster using an identical control-panel path. The overlap points to one shared backend distributing rebranded commodity stealers rather than five unrelated campaigns.
Eleven Windows payloads carrying five different VirusTotal threat labels — Amadey/Lumma, Stealc, ClipBanker/Cerbu, Kasidet/Fragtor, and Barys — all check in with the same small cluster of IP addresses using a verbatim-identical control-panel path. That's not a coincidence of naming; it's a shared backend wearing five different masks, and it's the detail that makes this cluster worth a second look rather than five separate incident tickets. The path reuse is concrete and traceable.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read