C&CMembers
C&C

One Build, Four AV Labels: Inside a Stealer Masquerade Pipeline

Four files carrying different antivirus family labels—Injuke, ClipBanker, StealC, Mikey—share an identical imphash and rich header hash, revealing a single build pipeline masquerading as svchost.exe and other core Windows processes. The operation pairs this fragmentation trick with a signed-but-expired BYOVD driver and a CMSTP UAC bypass, backstopped by disposable AS214351 infrastructure.

Sep 29, 2026, 14:44 (UTC+9)Last seenSep 29, 2026Severity100ByCTX TeamActorWizard SpiderGrim SpiderIOC39MITRE20RegionsBE

Four files carrying four different antivirus threat labels — trojan.injuke/hrgx, trojan.clipbanker/hrgz, trojan.stealc/stealer, and trojan.mikey/clipbanker — turn out, on closer inspection, to be the same binary wearing different clothes. All four share an identical import-table hash (75c410d3cdd17cf4a33ccaf94384484f) and an identical rich PE header hash (dee6ab558f324ac40038942e3c424ed4), a level of structural identity that has nothing to do with coincidence and everything to do with a single…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence