Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismthreat-infrastructure-trackingcommand-and-control-methodcredential-stealer-activity

Signed Malware Installers and Live C2 Infrastructure Fuel Multiple Loader Campaigns

Updated 2mo agoFirst seen Apr 21, 20266 sources

Breakglass Intelligence identified several active malware delivery operations using signed installers, compromised websites, and live command-and-control infrastructure to distribute loaders, stealers, and remote access tools. One campaign used the newly registered domain maybedontbanplease[.]com as CastleLoader C2 on 3NT Solutions LLP infrastructure, with a large NSIS installer embedding Python 3.14, AES-encrypted payloads, and in-memory shellcode execution via pythonw.exe; the installer was signed with an EV certificate issued to the likely fictitious entity SERPENTINE SOLAR LIMITED. The activity was attributed with medium-high confidence to GrayBravo and linked to delivery of LummaC2, StealC, RedLine, Rhadamanthys, DeerStealer, NetSupport RAT, and SectopRAT, with targeting that included U.S. government, critical infrastructure, IT, and logistics organizations.

A separate operation distributed a trojanized MSTeamsSetup.exe that installed a weaponized RustDesk client and communicated with mon.systemautoupdater[.]com on EvoXT infrastructure, while presenting a TLS certificate for calipology[.]com, tying the activity to the GeorgeGinx/Striker operator. In another live campaign, attackers used the compromised Syrian web development site allsydevs[.]com to host an obfuscated .NET loader masquerading as a WordPress image and connected victims to 172[.]93[.]167[.]12:4263 over HTTPS using a self-signed certificate with the fake common name Mesh Data; at least six related samples were linked to the same C2, with lure names suggesting targeting of Middle Eastern construction and export firms. Together, the investigations show financially motivated actors expanding malware distribution through fraudulent code-signing, trojanized business software, and hijacked web infrastructure.

Share:
Signed Malware Installers and Live C2 Infrastructure Fuel Multiple Loader Campaigns
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 10, 20262mo ago

Breakglass exposes live AllSyDevs multi-campaign malware operation

Breakglass reported that a compromised Syrian web development server, allsydevs[.]com, was hosting a .NET malware loader disguised as a WordPress image file, with a separate live C2 at 172[.]93[.]167[.]12:4263. The analysis tied at least six samples to the operation and described AES decryption, process injection, and targeting of Middle Eastern construction and export businesses.

Apr 9, 20262mo ago

Breakglass identifies signed MSTeams installer delivering RustDesk malware

Breakglass reported that mon.systemautoupdater[.]com on 23.27.141[.]44 was active infrastructure for a trojanized Microsoft Teams installer that deployed a weaponized RustDesk client. The infrastructure and TLS artifacts linked the activity to the previously identified GeorgeGinx/Striker operator using the "calipology" handle.

Breakglass documents live CastleLoader C2 and GrayBravo attribution

Breakglass reported that maybedontbanplease[.]com was being used as live CastleLoader C2 infrastructure resolving to 38[.]180[.]136[.]139, though the backend was down and only an nginx reverse proxy remained reachable. The report linked CastleLoader with medium-high confidence to GrayBravo and described delivery of multiple secondary payloads across U.S. government, critical infrastructure, IT, and logistics targets.

Apr 8, 20263mo ago

Trojanized MSTeams installer sample appears on MalwareBazaar

A malicious MSTeamsSetup.exe sample delivering a weaponized RustDesk client was first observed on MalwareBazaar. The installer was signed with a suspicious certificate issued to "Zlatin Stamatov."

Apr 2, 20263mo ago

AllSyDevs-linked stealer and RAT infrastructure is established

Infrastructure for the AllSyDevs operation was assessed as newly established in early April 2026, using compromised allsydevs[.]com hosting and a live C2 at 172[.]93[.]167[.]12:4263. The campaign supported multiple malware samples targeting mainly Middle Eastern commercial entities.

CastleLoader C2 domain maybedontbanplease.com is registered

The domain maybedontbanplease[.]com, later identified as CastleLoader command-and-control infrastructure, was newly registered. Breakglass later tied it to GrayBravo-linked malware activity.

Mar 18, 20263mo ago

ThreatFox flags 172.93.167.12:4263 as botnet C2

ThreatFox identified 172.93.167.12:4263 as botnet command-and-control infrastructure. This indicator was later linked to the AllSyDevs multi-campaign stealer and RAT operation.

Mar 14, 20263mo ago

Breakglass reports signed IcedID MSI delivering Latrodectus

Breakglass analyzed a malicious signed MSI file, info_IR-99661418.msi, used as an IcedID Stage-1 dropper via the WiX custom action framework to execute an embedded .NET assembly and launch an IcedID DLL with rundll32.exe. The report said the malware beaconed to statifaronta.com and retrieved a Latrodectus Stage-2 payload tied to active infrastructure on 45.61.136.30, assessing the activity as a live ransomware-precursor campaign linked with medium-high confidence to TA577 or TA551-aligned operations.

IcedID / Latrodectus - Signed WiX MSI Dropper Campaign - Breakglass Intelligence - Breakglass Intelligence
Mar 12, 20263mo ago

Breakglass identifies Pulsar RAT v2.4.5 MSI campaign

Breakglass reported an active campaign using a Windows Installer named haunt.msi, first seen on 2026-03-12, to deliver Pulsar RAT v2.4.5 through a multi-stage loader that disables AMSI, ETW, and WLDP. The report said command-and-control traffic was proxied through host.fedmenigga.workers.dev on Cloudflare Workers to a backend at 31.57.147.207 and assessed the actor as operating a sustained multi-tool campaign since at least February 2026.

Pulsar RAT v2.4.5 - MSI Dropper with GUID-Encoded Shellcode & Cloudflare Workers C2 - Breakglass Intelligence - Breakglass Intelligence
Mar 5, 20264mo ago

Breakglass identifies CryptoVista trojanized installer signed with stolen EV certificate

Breakglass reported a trojanized installer impersonating CryptoVista that was signed with a freshly issued SSL.com EV code-signing certificate belonging to TRUST & SIGN POLAND, a Docaposte subsidiary. The sample appeared by March 5, 2026 and used an Inno Setup-based loader with ChaCha20 encryption, XOR obfuscation, geofencing, and process injection, while achieving 0/36 AV detections as of March 10.

CryptoVista Trojanized Installer: Stolen Docaposte EV Certificate Achieves 0/36 AV Detection While Impersonating Legitimate Crypto Brand - Breakglass Intelligence - Breakglass Intelligence
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

107 LINKEDOpen in app
Vulnerabilities
1 linked
Affected products
28 linked
Windows.Net FrameworkOpensshLitespeed Web ServerPhpWindows InstallerWordpressRustdeskNullsoft Scriptable Install SystemWindows 11FreetypeWindows 10ImagemagickWindows Server 2022Brave BrowserFirefoxNginxRedisElasticsearchPythonUbuntuOperaCloudflare CdnChromeMicrosoft Defender For EndpointWindows Remote DesktopInno SetupHyper-V
Organizations
53 linked
Breakglass IntelligenceGoDaddyCloudflareHetzner Online GmbHNexeon Technologies, Inc.Amanah Tech Inc.Hosting SrbijaRealtime Register B.V.Al Fadala ExportAmazon Web ServicesSectigoMicrosoft CorporationSSL.comGoogleCloudwaysGlobalSignBlackpoint CyberDigitaloceanElasticTeam CymruSquarespaceReversingLabsDarktraceNameCheapProofpoint3NT Solutions LLPBitdefenderTucowsabuse.chNetlifyBl NetworksCogent CommunicationsHurricane ElectricURLscan.ioFranTech SolutionsNICENIC INTERNATIONAL GROUP CO., LIMITEDGlobal Domain Group LLCCertumLet us EncryptEvoxtCalipologyCAPE SandboxLa Poste GroupIDEMIA POLAND R&D SP Z O ODocaposteCryptoVistaSprious LLC12651980 CANADA INC.SquiblydooBlogBELLAP LIMITEDipwhois.ioSERPENTINE SOLAR LIMITEDTRUST & SIGN POLAND SP Z O O
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.