C&CMembers
C&C

Shared Panel Path Ties Five Rebranded Stealers to One C2 Backend

Eleven Windows payloads carrying five different VirusTotal labels — Amadey/Lumma, Stealc, ClipBanker/Cerbu, Kasidet/Fragtor, and Barys — all check in with the same small IP cluster using an identical control-panel path. The overlap points to one shared backend distributing rebranded commodity stealers rather than five unrelated campaigns.

Sep 16, 2026, 22:53 (UTC+9)Last seenSep 16, 2026Severity100ByCTX TeamIOC35MITRE60RegionsBA

Eleven Windows payloads carrying five different VirusTotal threat labels — Amadey/Lumma, Stealc, ClipBanker/Cerbu, Kasidet/Fragtor, and Barys — all check in with the same small cluster of IP addresses using a verbatim-identical control-panel path. That's not a coincidence of naming; it's a shared backend wearing five different masks, and it's the detail that makes this cluster worth a second look rather than five separate incident tickets. The path reuse is concrete and traceable.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence