
Wizard Spider Kit Adds Stealer-to-Downloader Handoff, C2 Unchanged
Two new files — a stealc-tagged dropper and a service-masquerading downloader — share a single YARA rule and identical IDS signatures, evidencing a fresh two-stage handoff inside a known kit. The command-and-control layer beneath it hasn't moved: three IPs on one German AS still front kucoin.sh and *.polymarket.ac impersonation certificates.
The kit CTX Team has tracked under this cluster just picked up a matched pair of new files, and they slot together like a delivery chain missing its middle link. A stealc-tagged dropper — carried under the path %APPDATA%\crkhost.exe and flagged malicious by 55 of 76 engines — and a downloader dressed as a Windows service process, taskhostw.exe (also seen as WinUpdateHelper.exe, 46/76 detections), both first appeared within a 24-hour window in early May and both share a single YARA signature:…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read