⚠️ Malware / Trojaner / VirenSindriKit V2.0.0 (C framework to decouple technique logic from execution mechanics)(15.09.2026 um 17:48 Uhr)
🕵️ SicherheitslückenHeap-Buffer-Überlauf im Discord-Backend(15.09.2026 um 18:21 Uhr)
⚠️ Malware / Trojaner / VirenLooking for dedicated beginner ctf buddies(15.09.2026 um 21:03 Uhr)
🐧 Linux TippsBEING A GREAT HACKER(16.09.2026 um 00:54 Uhr)
⚠️ Malware / Trojaner / Viren0xCr0ssCrush - Windows BYOVD Ring 0 Exploit(16.09.2026 um 01:40 Uhr)
⚠️ Malware / Trojaner / VirenI Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table(16.09.2026 um 16:03 Uhr)
⚠️ Malware / Trojaner / VirenSindriKit V2.0.0 (C framework to decouple technique logic from execution mechanics)(15.09.2026 um 17:48 Uhr)
🕵️ SicherheitslückenHeap-Buffer-Überlauf im Discord-Backend(15.09.2026 um 18:21 Uhr)
⚠️ Malware / Trojaner / VirenLooking for dedicated beginner ctf buddies(15.09.2026 um 21:03 Uhr)
🐧 Linux TippsBEING A GREAT HACKER(16.09.2026 um 00:54 Uhr)
⚠️ Malware / Trojaner / Viren0xCr0ssCrush - Windows BYOVD Ring 0 Exploit(16.09.2026 um 01:40 Uhr)
⚠️ Malware / Trojaner / VirenI Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table(16.09.2026 um 16:03 Uhr)
⚠️ Malware / Trojaner / Viren 🕛 vor 1 Monat 3 Min Lesezeit SECURITY-FEED
0

A StealC backend I reported in April still exposes its documented malware routes after Operation Endgame

↗ Quelle (reddit.com)
🔬 IoC Intelligence (1 Indikatoren erkannt)
62[.]60[.]226[.]113
🗣️ Stimme:

In April, I analyzed a StealC v2 campaign distributed through 19 GitHub typosquat repositories. One of the repositories impersonated my own open-source project.

The delivery chain was:

CODE
GitHub typosquat -> Python dropper -> api.nailproxy.space -> encrypted Windows loader -> StealC v2 DLL -> spellmarketplace.club / 62.60.226.113:6673 

GitHub eventually removed all 19 repositories.

I separately reported the backend indicators to the relevant registrars, Cloudflare, the hosting provider, CERT-Bund, GitHub Security Lab, ThreatFox, and AlienVault OTX.

Then Operation Endgame disrupted infrastructure associated with SocGholish, Amadey, and StealC. Europol reported 326 servers and 142 domains actioned, while Microsoft said it moved against more than 200 malicious Amadey and StealC C2 domains and IPs.

Three months after my original disclosure, I checked the known infrastructure again using only minimal unauthenticated GET/HEAD requests.

The two malware-specific routes still behave differently from an arbitrary control path:

CODE
GET /api/v1/auth/session -> 405 Method Not Allowed GET /api/v1/data/sync -> 405 Method Not Allowed GET /foo/bar/baz -> 404 Not Found 

HEAD produces the same status codes for these three paths.

My interpretation is deliberately narrow:

  • The known application routes remain registered and reachable.
  • This does not prove that payload delivery, authentication, or exfiltration still works.
  • I did not send the HMAC handshake, trigger Stage 2, or interact with the malware protocol.

There was another odd result: on both spellmarketplace.club/ and the bare IP root path, GET returned 404 while HEAD returned 200 at the same moment. I therefore do not treat the root-path checks as reliable evidence that the complete backend is operational.

The monitoring evidence also has limitations. A daily cron produced only 18 measurements over 69 days, with gaps of up to 20 days. The delivery and exfiltration endpoints also briefly became unreachable in late May. I included those details rather than presenting the infrastructure as continuously available.

The useful distinction for me is:

A large operation can successfully disrupt hundreds of malicious systems while a specific previously reported backend still exposes its known routes.

The full write-up includes the original kill chain, reporting timeline, ThreatFox/OTX submissions, current probe results, and the limits of what can be concluded without actively engaging the malware protocol:


Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf reddit.com.
↗ Original-Artikel auf reddit.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Built a PPL-aware ALPC enumerator because standard handle duplication was leaving blind spots in the attack surface
1 Quelle
SindriKit V2.0.0 (C framework to decouple technique logic from execution mechanics)
1 Quelle
Heap-Buffer-Überlauf im Discord-Backend