home.social

#stealcv2 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #stealcv2, aggregated by home.social.

fetched live
  1. 2025-08-20 (Wednesday): #SmartApeSG for fake #CAPTCHA page with #ClickFix instructions that led to an MSI file for #NetSupport #RAT and the #NetSupportRAT infection led to #StealCv2.

    Malware samples, a #pcap, and indicators at www.malware-traffic-analysis.net/2025/08/20/index.html

  2. 2025-06-18 (Wednesday): #SmartApeSG --> #ClickFix lure --> #NetSupportRAT --> #StealCv2

    A #pcap of the traffic, the malware/artifacts, and some IOCs are available at malware-traffic-analysis.net/2.

    Today's the 12th anniversary of my first blog post on malware-traffic-analysis.net, so I made this post a bit more old school.

  3. StealC v2 and Aurotun Stealer seem to be interconnected. They are sometimes deployed as part of the same infection chain and share C2 infrastructure.

    Example: tria.ge/250411-f3d2tszyhy/beha
    👾 StealC v2: 62.60.226.114:80
    👾 Aurotun: 62.60.226.114:40101
    #AurotunStealer #StealCv2