APTMembers
APT

Wizard Spider Kit Adds Stealer-to-Downloader Handoff, C2 Unchanged

Two new files — a stealc-tagged dropper and a service-masquerading downloader — share a single YARA rule and identical IDS signatures, evidencing a fresh two-stage handoff inside a known kit. The command-and-control layer beneath it hasn't moved: three IPs on one German AS still front kucoin.sh and *.polymarket.ac impersonation certificates.

Aug 5, 2026, 22:04 (UTC+9)Last seenAug 5, 2026Severity100ByCTX TeamActorWizard SpiderGrim SpiderIOC14MITRE25RegionsJO

The kit CTX Team has tracked under this cluster just picked up a matched pair of new files, and they slot together like a delivery chain missing its middle link. A stealc-tagged dropper — carried under the path %APPDATA%\crkhost.exe and flagged malicious by 55 of 76 engines — and a downloader dressed as a Windows service process, taskhostw.exe (also seen as WinUpdateHelper.exe, 46/76 detections), both first appeared within a 24-hour window in early May and both share a single YARA signature:…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence