APTMembers
APT

TA511 Bundle Deploys StealC v2 With Chrome Encryption Bypass via Single German AS

A coordinated four-family malware campaign attributed to TA511 has concentrated every command-and-control endpoint inside a single autonomous system registered in October 2024 and geolocated to Germany. The bundle's most significant capability is StealC v2's bypass of Chromium app-bound encryption, a browser credential protection now defeated at the commodity crimeware tier and distributed via the Amadey loader-as-a-service ecosystem.

Jun 15, 2026, 10:15 (UTC+9)Last seenJun 15, 2026Severity100ByCTX TeamActorTA511MAN1IOC42RegionsCL

##A Four-Family Payload Bundle Targets Browser Credentials and Crypto Wallets From a Single German Hosting Fabric A coordinated malware campaign deploying Amadey, StealC v2, LummaC2, and ClipBanker as a unified payload bundle has concentrated every observed command-and-control endpoint inside a single autonomous system — AS214351, operated by Femo It Solutions Limited — a RIPE NCC-registered provider that came into existence in October 2024 and whose IP space spans just two /24 subnets…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence