Refuting the Seedworm Attribution of Commodity MaaS

SubjectSeedworm / MuddyWater attribution of CastleLoader, DeonoRAT, CastleRAT, Tsundere Bot, and ClixFlare infrastructure
AssessmentAttribution is incorrect as stated — commodity MaaS misidentified as Iranian state capability
ConfidenceHIGH
Last UpdatedJuly 29, 2026

Tommy M — @ffforward

This is an independent, personal research publication. The analysis, findings, and opinions expressed are solely my own and do not represent the views, positions, or endorsement of my employer or any organization I am affiliated with. This work was conducted independently, on my own time, and has not been reviewed, approved, or sponsored by my employer.

This all started while working with the infosec community to document an undocumented ClickFix chain that had been running for over six months without proper public documentation — built around a C2 panel called ClixFlare. I noticed the chain commonly led to CastleLoader MSIs, and while investigating that infrastructure, I suddenly found myself in the midst of supposedly Iranian APT activity.

The reason: one of the ClixFlare PowerShell staging servers I was investigating, hxxps://iuumfgrrnuhb[.]zhivachkapro[.]com/pobor, turned out to be the first IOC listed in Cisco Talos's blog on Seedworm a.k.a. MuddyWater, published in connection with the current Iran crisis.

ClickFix and ClixFlare had to wait. This would go deep.

Contents
1. Executive Summary
2. The Core Claim Under Test
3. The Foundational Flaw: An Uncitable Appeal to Authority
4. Master Forensic Synthesis — Summary Assessment
5. The 10 Chains — Summary Table
6. Attribution Ecosystem Timeline
6b. Case Studies in Attribution Failure
7. Real vs. Fabricated MuddyWater
7b. Deep Technical Evidence & Historical Precedent
Appendix A — Full Reconstructed Attack Chains (1–10)
Appendix B — Certificate Table
Appendix C — Full IOC Hash Table
Appendix D — Full Infrastructure Table
References

1. Executive Summary

In March 2026, Symantec/Broadcom published a threat intelligence report attributing a cluster of intrusion activity targeting U.S. banks, airports, software firms, and Canadian non-profits to Seedworm/MuddyWater, an Iranian MOIS cyber espionage unit [1]. Over the following months, this attribution was echoed and expanded by Cisco Talos [2], Check Point [3], Rapid7 [4], CyberProof [5], and JUMPSEC [6] — creating an industry consensus that four malware pillars ("Dindoor", "Fakeset", Stagecomp/Darkcomp, and Tsundere Bot) represented active Iranian state capability.

Why this matters:

This document tests the vendor thesis against ground-truth forensic evidence across 10 reconstructed attack chains, and finds zero technical APT indicators in nine of them.

2. The Core Claim Under Test

Symantec found two malware families on the networks of a U.S. bank, airport, software company (Israeli operations), and a Canadian non-profit, and grounded the Seedworm attribution in a single certificate-reuse argument:

"The Donald Gay certificate has been used previously to sign malware linked to Seedworm… The Stagecomp and the Darkcomp malware have been linked to Seedworm by vendors including Google, Microsoft and Kaspersky. While this malware wasn't seen on the targeted networks, the use of the same certificates suggests the same actor — namely Seedworm — was behind the activity." — Symantec [1]

The Core Research Question: Does empirical binary analysis, C2 telemetry, and infrastructure profiling support this state-sponsored attribution, or did vendors launder commercial cybercrime MaaS into Iranian state lore? The following sections test the vendor thesis against ground-truth forensic evidence across 10 reconstructed attack chains.

3. The Foundational Flaw: An Uncitable Appeal to Authority

The entire March 2026 Seedworm attribution hangs on a single foundational assertion: that the "Donald Gay" certificate previously signed Stagecomp and Darkcomp, which Symantec claims "have been linked to Seedworm by vendors including Google, Microsoft and Kaspersky." A rigorous audit of this claim reveals it appears to be unsupported by any independently verifiable source.

Trojan.Stagecomp and Trojan.Darkcomp are Broadcom/Symantec proprietary detection names — no other vendor tracks malware under these names. The Stagecomp/Darkcomp → Seedworm link that Symantec cites as prior art from "Google, Microsoft and Kaspersky" cannot be independently located or verified in any of those vendors' published research.

If the prior Stagecomp/Darkcomp → Seedworm attribution cannot be independently verified, the entire chain collapses. The "Donald Gay" certificate signed multiple things, but the assertion that those things belong to Seedworm is an uncitable appeal to authority — and every downstream vendor report inherits this single unverified anchor point.

4. Master Forensic Synthesis — Summary Assessment

Deconstructing the four pillars of vendor attribution reveals that every cited indicator belongs to commercial Malware-as-a-Service (MaaS) and retail cybercrime. What follows is not four isolated technical notes but four independent confirmations of the same underlying pattern: proprietary detection names created the illusion of distinct APT toolsets, when in fact each "family" is a component of commodity crimeware sold to any paying customer.

Pillar 1: "Dindoor" Is Just CastleLoader

Trojan.Dindoor is simply Symantec's proprietary name for the Deno-based staging build of CastleLoader (TAG-150) and its detonation artifacts. CastleLoader is a well-documented commercial MaaS platform independently tracked by Recorded Future, eSentire, and PRODAFT, and sold to dozens of paying cybercrime affiliates and ransomware operators worldwide — meaning Symantec attributed a rental product to a single state actor.

Pillar 2: "Fakeset" — the SEO Malvertising Story

This pillar most clearly exposes the absurdity of the state-sponsorship claim. Trojan.Fakeset is not a bespoke espionage implant — it is a sprawling, retail-grade SEO and malvertising operation, distributing portable Python loaders through public Backblaze B2 buckets registered under whimsical, teenage-coded names: gitempire, elvenforest, oceanhub, and sailormercuryfam.

These buckets hosted trojanized installers for ordinary consumer and professional software — Blender 3D, ProCore, HWMonitor — the kind of tools an engineer or hobbyist would search for and download in seconds. Vendors captured only a tiny slice of this ecosystem, anchored entirely to two commercially-purchased MSaaS code-signing certificates issued to "Amy Cherne" and "Donald Gay." The real campaign is vastly larger, spanning C2 domains including maybedontbanplease[.]com, mazafakaerindahouse[.]info, and mofa****gas[.]info.

Accepting the vendor attribution requires believing that Iranian MOIS operators run Google Ads campaigns for Blender 3D and ProCore, then route stolen credentials through a command-and-control server named mofa****gas[.]info. No serious operational defender accepts this.

Ground-truth URL telemetry for Trojan.Fakeset samples confirms they were downloaded from open Backblaze B2 buckets (gitempire.s3, elvenforest.s3) hosting fake HWMonitor, Notion, Obsidian, Blender, and SketchUp installers. When executed, these portable Python loaders drop pythonw.exe and call home to juvenile edgelord C2 domains — naming conventions of a bored teenager running a malvertising side-hustle, not a signals-intelligence directorate. It is precisely the kind of detail vendors omitted from their public IOC tables, publishing SHA-256 hashes while quietly leaving the domain names out of the report.

Some independent researchers track this Fakeset infrastructure as a CastleLoader variant rather than a distinct family. I have not been able to independently confirm this classification, as the relevant C2 servers were no longer active at the time of this analysis.

The IronPython .NET LOLBin Stager (Fakeset Infrastructure)

A separately observed installer script associated with the sedaliarealty[.]net cluster — part of the same Fakeset SEO malvertising ecosystem — reveals an evolutionary tradecraft leap: rather than deploying portable CPython, the affiliate abuses IronPython running on the .NET Common Language Runtime, downloading the IronPython release directly from the official GitHub repository and using a UTF-32-padded Base64 payload to evade YARA string scrapers — a technique optimized for evading Python-signature detections, not a hallmark of nation-state tradecraft.

The 12-Month C2 Infrastructure Rosetta Stone (Fakeset Infrastructure)

Pivoting on the custom HTTP backend's hardcoded JSON 404 signature ({"code":404,"success":false,"message":"File not found"}) — unique to the Fakeset delivery infrastructure — across URLScan, Censys, and Shodan retrieves an unbroken 12-month historical record of every C2 server operated by this single affiliate, spanning three evolutionary phases from standard /service/download/ staging, to UUID-segmented Python dropper paths (the exact window Symantec captured as "Fakeset"), to the current phase of throwaway edgelord domains. Every domain across all 61 historical records shares the identical JSON error signature and the same bulletproof/reseller ASN hosting profile (Servinga, Eonix, Scalaxy, Latitude.sh) — a signature of one ongoing retail malvertising operation, not intermittent state tasking.

Pillar 3: "Stagecomp" and "Darkcomp" — Amateur Loaders, Not State Tools

Trojan.Stagecomp and Trojan.Darkcomp are simplistic, amateur C++ loader and RAT binaries compiled for a short-lived QuickAssist/Teams initial-access-broker (IAB) campaign. Only two hashes of each malware family have ever been publicly recovered — a vanishingly small sample size on which to anchor an entire nation-state attribution. One sample, ms_upd.exe, was hosted on 172.86.126.208 — the exact same server hosting an amateur Coinbase real-time OTP-intercepting crypto-draining kit (stats-coinbase[.]com, "tryanotherway" kit), placing supposed Iranian state malware on shared infrastructure with retail crypto-theft tooling.

Pillar 4: "Tsundere Bot" — Russian-Language Commodity Loader

Tsundere Bot is a Node.js loader using EtherHiding (blockchain-based C2 resolution), and it contains explicit Russian-language developer error strings — "❌ Ни один RPC провайдер не вернул валидный IP" ("Not a single RPC provider returned a valid IP"). Its only vendor tie-in to the broader case was an exposed Python SimpleHTTP staging server (terymar[.]com) hosting Spf.ps1 and reset.ps1 alongside CastleLoader MSIs and AnyDesk — a configuration matching exactly what commercial Pay-Per-Install (PPI) botnets like Amadey and GCleaner distribute to any paying affiliate.

Verdict: Every attributed artifact belongs to commercial ecrime platforms, stolen or purchased MSaaS signing certificates, and shared initial-access-broker staging servers. No pillar survives independent scrutiny as evidence of Iranian state capability. This is our assessment based on the evidence presented.

5. The 10 Chains — Summary Table

From the IOCs shared across all vendor reports, we reconstructed 10 distinct attack chains. Full technical detail for each chain (hashes, VBS/PS1 filenames, byte counts, JWT payloads) is preserved in 7b. Deep Technical Evidence & Historical Precedent
Appendix A for independent verification.

ChainStages AnalyzedAPT Indicators FoundBasis of Vendor Attribution
1 — ClixFlare → clickzpaqkvba4 stages❌ ZeroSymantec: Trojan.Dindoor label [2]
2 — ClixFlare → Kilo524 stages❌ ZeroSymantec: Trojan.Dindoor label
3 — coupon.hub.v13 stages❌ ZeroSymantec: Trojan.Dindoor label; JWT matches JUMPSEC's chain
4 — Serial3 stages❌ ZeroSymantec: Trojan.Dindoor label
5 — eSentire ITW6 stages❌ ZeroeSentire: no APT attribution; Symantec: Trojan.Dindoor label
6 — QuickAssist/terymar4 artifacts❌ ZeroTalos: echoed Symantec's label [2]
7 — Stagecomp/Darkcomp3 stages⚠️ Certificate only"Donald Gay" cert → uncitable prior Seedworm link
8 — GCleaner/Amadey → CastleLoader/Smokest1206 stages / 12 hashes❌ ZeroJUMPSEC / vx-underground / BitSight: commodity Amadey distribution (Jan 2026); no APT attribution
9 — PsExec SEO3 stages❌ ZeroAV signature: Trojan.MuddyWater.10
10 — CyberProof Teams / update_ms3 stages❌ ZeroCyberProof: "Seedworm Teams Campaign" (July 2026); inherits Symantec label

Conclusion: Across 10 reconstructed chains covering 35+ stages and artifacts, the only technical APT indicator is a code-signing certificate purchasable from criminal MSaaS vendors ($5k–$9k via Fox Tempest). Every other attribution claim is vendor label inheritance — Symantec named the tool, and downstream threat intelligence feeds cascaded the attribution without empirical verification.

6. Attribution Ecosystem Timeline

Because vendors discovered TAG-150's modular framework independently across different staging runtimes (Deno, Python, Node.js), they assigned conflicting proprietary names to the same underlying components:

TAG-150 StageRecorded Future / JUMPSEC / ThreatDownSymantec / BroadcomeSentire
Stage 1 Stager (Deno JS eval-loop / WiX MSI)CastleLoader / CastleBotDindoorDinDoor / DenoRAT [17]
Stage 2 Core RAT (Python / C++ PE stealer)CastleRATFakesetNightshadeC2 [8]
EtherHiding Stager (Node.js + Smart Contract C2)ChainShell [6]Tsundere Bot [16]

Following Symantec's March 5, 2026 report, multiple vendors echoed and expanded the attribution, creating a circular feedback loop:

In-the-wild telemetry confirms ms_upd.exe was hosted on the same Cloudzy VPS server (172.86.126.208) that concurrently ran a live-panel Coinbase/Ledger crypto-draining kit. Rapid7's "Iranian state false flag" was simply a financially motivated ecrime affiliate running tech-support scams, crypto drainers, and Chaos ransomware on cheap VPS infrastructure.

6b. Case Studies in Attribution Failure

Beyond the general pattern of vendor label inheritance, three specific documented episodes reveal the exact mechanics by which commodity ecrime artifacts were laundered into "Seedworm" lore.

IDA Disassembly & Moniker Evolution (SmokestEdge120 → VirtualSmokestGuy120)

Unpacked process memory disassembly reveals that "SmokestEdge120" evolved into "VirtualSmokestGuy120" as internal scheduled task monikers. JUMPSEC cited "Amy Cherne -> Smokest JWT -> VirtualSmokestGuy" as their primary attribution chain. However, every link in that chain is a commodity ecrime artifact: "Amy Cherne" is an Azure MSaaS certificate receipt, "Smokest" is an Amadey/TopWebComics affiliate tag, and "VirtualSmokestGuy120" is simply a scheduled task string. Independent researchers, including Simon Kenin (@k3yp0d, "The water is so muddy that you can't see..."), confirmed that treating "Smokest" as an Iranian APT family was a complete analytical misinterpretation [7].

Deconstructing Symantec's May 12, 2026 Report ("Seedworm Electronics")

Symantec's follow-up report on May 12, 2026 ("Seedworm Electronics Campaign", Reference [15]) contains three fundamental analytical errors:

The "Operation Olalampo" Open Directory Contamination (Group-IB, February 2026)

Group-IB's February 2026 report ("Operation Olalampo", Reference [13]) encapsulates how open-directory scraping created a circular attribution loop. Group-IB discovered a Python SimpleHTTP/0.6 open directory containing a mix of active QuickAssist scam tools (lpu.exe, lpu.dll, reset.ps1), commercial remote-monitoring tools (AnyDesk, resocks), and legacy artifacts (FMAPP.dll, chrome_inject.exe).

The subsequent vendor lineage shows a clean chain of escalating certainty with no additional evidence added at each step:

An open Python SimpleHTTP directory on a VPS node (e.g. terymar[.]com) represents shared staging infrastructure — whether used by initial access brokers supplying multiple buyers, or by overlapping unrelated ecrime intrusions. Treating an exposed directory listing as a monolithic state-sponsored toolkit fundamentally misrepresents how shared MaaS staging infrastructure operates.

7. Real vs. Fabricated MuddyWater

Independent research from Ctrl-Alt-Intel (March 4, 2026) [7] and Group-IB (February 2026) [13] documents what genuine MuddyWater state espionage operations actually look like, in stark contrast to the commodity crimeware attributed here.

AttributeReal MuddyWater Operations (Ctrl-Alt-Intel / Group-IB)Symantec "Seedworm" Attribution
Delivery VectorMacro-based spearphishing, Fortinet CVE exploitationSEO-poisoning malvertising, ClickFix, Teams/QuickAssist lures
Malware SuiteCustom: GhostFetch, GhostBackDoor, KeyC2, PersianC2, CHARCommodity MaaS: CastleLoader, DenoRAT, NightshadeC2, Tsundere Bot
C2 InfrastructureCustom Flask/Python backends, Telegram bots, dedicated IPsMulti-tenant MaaS endpoints (serialmenot[.]com, terymar[.]com)
Language/ArtifactsPersian keyboard mappings, Farsi source stringsRussian developer strings, CIS exclusions
TargetingMENA government, aviation, telecom, healthcare (Israel, UAE, Jordan)Broad global consumer & enterprise targets via mass ClickFix/SEO

7b. Deep Technical Evidence & Historical Precedent

Beyond the chain reconstructions and case studies, several additional pieces of evidence independently corroborate the commodity-MaaS thesis and directly preempt the strongest counter-argument: that Iranian state actors could simply be using commodity tools rather than developing them.

Kaspersky's Independent Heuristic Contradicts the Western Vendor Consensus

An unanalyzed VirusTotal Intelligence sample of the DenoRAT C2 JavaScript module (a2183b4d..., 715.80 KB) carries only a 6/61 detection score. Four Western AV vendors (Avast, AVG, Avira, WithSecure) blindly flag it as JS:Muddywater-A via signature inheritance from Symantec's attribution post. Kaspersky, however, detects its actual functional nature: HEUR:Trojan-PSW.Script.Disco.gen — a password-stealing-ware and Discord/credential-stealer classification, with no APT designation whatsoever.

Deobfuscating this sample (46,486 AST transformations, 12,033 decoded strings) empirically validates Kaspersky's heuristic and reveals the RAT's true architecture: native Windows DPAPI decryption via Deno's FFI (CryptUnprotectData against Chromium login/cookie databases), a credential and crypto harvesting engine targeting 58 browser extension IDs, Discord tokens, Telegram sessions, and 19 desktop/browser crypto wallet families, plus a bidirectional WebSocket C2 for interactive PowerShell execution.

Iranian MOIS state espionage units do not deploy commodity Discord-token and 58-extension cryptocurrency-wallet stealers. This is retail infostealer tooling, independently confirmed as such by Kaspersky's own detection engine.

Resolving the "Amadey Paradox"

vx-underground's January 2026 analysis expressed confusion at finding an Amadey botnet panel on the same server hosting a sophisticated polymorphic JS payload, noting it would be "unusual... for an obfuscated polymorphic multi-staged Javascript payload to deliver Amadey." Empirical reconstruction resolves the paradox by reversing the assumed direction: Amadey Bot was the parent PPI stage (dropped via Nullmixer/GCleaner), and Amadey's C2 tasked infected hosts to download the CastleLoader MSI and CastleRAT payloads as secondary tooling — not the other way around. The JWT embedded in the MSI (userNote: "topwebcomics") directly matches the web-comic lure vx-underground identified.

Historical Proof: eSentire's September 2025 Report Pre-Dates the Attribution by Six Months

eSentire's foundational report, "New Botnet Emerges from the Shadows: NightshadeC2" (published six months before Symantec's Iranian attribution), documented an earlier .NET/PowerShell CastleLoader build distributing NightshadeC2 and Lumma Stealer via commodity ClickFix landing pages and trojanized SEO software (CCleaner, Advanced IP Scanner, Express VPN). The report documented a Steam Community dead-drop C2 resolver, a SilentCleanup LOLBin UAC bypass, hidden HVNC browser sessions, and classic ClickFix PowerShell cradles — with zero Iranian APT attribution, proving CastleLoader was a thriving commodity affiliate loader long before Symantec rebranded it as "Dindoor."

A separately documented interactive AnyRun sandbox session from researcher JAMESWT (August 22, 2025) captured the operator taking manual control upon realizing they were in a sandbox, typing the taunt "are you dump?!" in Notepad and rage-deleting desktop icons before disconnecting. State-sponsored intelligence operatives conducting espionage do not behave this way — it is the unmistakable signature of a commodity cybercrime affiliate.

Historical Precedent: Iranian Actors Do Consume Russian Commodity Malware — But Leave Distinct Fingerprints

Iranian threat actors purchasing and deploying commodity Russian-developed malware is a documented historical pattern — but genuine cases show a clear division between purchased collection tools and custom-built components, unlike the Seedworm attribution where no custom component has ever been recovered.

CampaignIranian ActorCommodity Tool (Russian)CertificateCustom Tool (Genuinely Iranian)
F5UPDATER (2023)HandalaRhadamanthys (Asgard Protector)"Skytec Global Ltd" (purchased, revoked)Hatef wiper
INCD impersonation (Mar 2026)HandalaRhadamanthys (Asgard Protector)Non-reused Cloudflare domainsWiper
Ctrl-Alt-Intel server (Mar 2026)MuddyWaterTsundere Bot / ChainShell (TAG-150)"Amy Cherne" / "Donald Gay" (purchased)KeyC2, PersianC2
CastleRAT MaaS (2025–2026)Attributed to MuddyWaterCastleRAT, Stagecomp/Darkcomp (TAG-150)"Amy Cherne" / "Donald Gay" (purchased)None identified

The consistent pattern in genuine cases: Iranian actors purchase commodity Russian malware for collection capabilities and purchase code-signing certificates from criminal MSaaS vendors, but their custom tools (wipers, Farsi-language C2 frameworks) remain separate and identifiable. The Seedworm/CastleRAT case is the outlier — it has a purchased certificate and commodity tooling, but conspicuously no custom Iranian-attributable component has ever been recovered, which is precisely what distinguishes genuine consumption from mistaken attribution.

Confidence Assessment

Appendix A — Full Reconstructed Attack Chains (1–10)

Full technical staging detail for all 10 chains, reproduced in complete forensic depth for independent verification.

A.1 — Chain 1: ClixFlare → clickzpaqkvba

Key finding: Triple-obfuscated PowerShell cradle from a Russian-slang delivery domain (/pobor) drives a CastleLoader MSI carrying the same "Smokest"/"BatClickFix" affiliate fingerprint used across multiple unrelated lure campaigns.

Vendors involved: Symantec [1], Cisco Talos [2], ThreatDown [10], Hunt.io [19]

Delivery domain zhivachkapro[.]com uses triple-layer obfuscation (garbage variable padding → reversed Base64 → reversed UTF-8 → iex), deobfuscating to a 3-line downloader that fetches clickzpaqkvba.msi (hash bd8203ab88983bc081545ff325f39e9c5cd5eb6a99d04ae2a6cf862535c9829a, ~23 KB, author Delta_daemon99, created 2026-02-02) and silently installs via msiexec /qn. This establishes HKCU\...\Run\Victor_script56 running wscript.exe november_block25.vbs, which launches PowerShell bootstrap charlie_script48.ps1 (3,181 bytes). The bootstrap checks for deno.exe, downloads it from deno.land if absent, binds TCP mutex 10044, and polls serialmenot[.]com/mv2/<JWT>/<id>. The extracted JWT reveals campaignId: "75cbe18653d52372", campaignName: "Smokest", userId: "bb47c0615477a877", userNote: "BatClickFix" — the same affiliate identity used in the TopWebComics Amadey distribution campaign (Jan 2026).

A.2 — Chain 2: ClixFlare → Kilo52

Key finding: Identical campaign fingerprint (campaignId 75cbe18653d52372, userId bb47c0615477a877) as Chain 1, proving the same commercial affiliate operated both lure variants.

Vendors involved: Symantec [1], Cisco Talos [2], ThreatDown [10], Hunt.io [19], CyberProof [5]

Same /pobor delivery cradle from zhivachkapro[.]com, this time invoking 7467f326677a4a2c8576e71a832e297e794ea00e9b67c4fcbe78b5aec697cec4.msi ("Kilo52.msi", ~23 KB, author Kilo52, created 2026-02-18). Drops zulu_worker10.vbs which runs charlie53.ps1, polling serialmenot[.]com/mv2/<JWT>/<id>. JWT reveals identical campaignId: "75cbe18653d52372", campaignName: "Smokest", userId: "bb47c0615477a877", userNote: "BatClickFix" as Chain 1.

A.3 — Chain 3: coupon.hub.v1

Key finding: A 1.08 MB "inflated" MSI is functionally identical to the standard ~22 KB CastleLoader build, padded with an inert dummy file purely to evade size-based heuristics.

Vendors involved: Symantec [1]

Coupon-lure MSI 0f9cf1cf8d641562053ce533aaa413754db88e60404cab6bbaa11f2b2491d542 (1.08 MB) is padded with an inert dummy file (Viper_widget65.dat). Author alpha_tool27, created 2026-02-13. Establishes HKCU\...\Run\Romeo60 running wscript.exe Viper_controller36.vbstango_utility84.ps1, polling serialmenot[.]com/mv2/<JWT>/<id>. JWT: campaignId: "75cbe18653d52372", campaignName: "Smokest", userId: "bb47c0615477a877", userNote: "ADS" — matching the same campaignId and userId that JUMPSEC uses as its primary MuddyWater attribution chain, but here explicitly tagged as ad-distribution/SEO lure delivery by the same commercial affiliate.

A.4 — Chain 4: Serial

Key finding: Separate customer identity (userId dea1196d5d4ab8d6, campaignName "test") proves a distinct QA/developer account from the "Smokest" production affiliate — undermining any single-actor narrative.

Vendors involved: Symantec [1], Check Point [3]

MSI 1d984d4b2b508b56a77c9a567fb7a50c858e672d56e8cf7677a1fca5c98c95d1 (22.5 KB, author echo_tool89, subject "Serial", created 2026-02-01) establishes persistence via wscript.exe Lynx_system59.vbs, running b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0 (named python85.ps1 as a decoy filename, despite containing zero Python code — it fetches deno.exe and executes Deno JavaScript). Polls serialmenot[.]com/mv2/<JWT>/<id>: campaignId: "6b357c4222050506", campaignName: "test", userId: "dea1196d5d4ab8d6" — a separate customer identity from Chains 1–3, indicating a developer or QA testing account. Cross-campaign code identity to Chain 8 proven via webcrack AST comparison.

A.5 — Chain 5: eSentire ITW

Key finding: Active ClixFlare ClickFix infrastructure observed live in June 2026, using Explorer-based process spoofing to break parent-child EDR detections.

Vendors involved: eSentire [8], ThreatDown [10], Hunt.io [19]

MSI 822ce21c572ac062ff55da8c94132f506af04ff919bf8f3bda848840076743b0 (12.8 KB, author echo_client41, subject "Mike51", created 2026-06-03) delivered via zclzgjjqewlzm1.msi from columbnezhjdq[.]com. Uses explorer.exe "[INSTALLFOLDER]\november85.cmd" instead of wscript.exe to break parent-child process tree detections, then runs Griffin20.ps1 which uses winget install --id DenoLand.Deno or scoop install deno instead of direct download. The server compiles launcher scripts on demand at webstizkgao[.]com/v02<BUILD_ID>.js — a tiny eval-loop fetching launcher-2, which sets up autorun and runs main via Deno.listen. Final payload is NightshadeC2, a native C++ PE backdoor using PEB_LDR_DATA evasion via /service/ HTTP C2, also dropping NetSupport/WarmCookie. Window class "IsabellaWine" matches the same TAG-150 MaaS template across unrelated builds.

A.6 — Chain 6: QuickAssist/terymar

Key finding: Live QuickAssist tech-support scam infrastructure serving both Tsundere Bot and a native credential-harvesting DLL from the same staging server, matching commodity scam TTPs exactly.

Vendors involved: Cisco Talos [2] ("Seedworm"), Blackpoint Cyber [14] (no APT attribution), Symantec [1] (May 2026)

Serial.msi (23a0a9b0755e052966b1e9e6137334444494c250afcf9f4a7e18c650cf2f4078) downloaded from terymar[.]com/install/Serial.msi (22.5 KB, author echo89, subject "oko", created 2026-02-03 22:14:10 UTC). Establishes HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Oscar15 running wscript.exe falcon13.vbs (445 bytes) → PowerShell bootstrap eagle_package6.ps1 (3,153 bytes). AV detections include Trojan:JS/MuddyWater.DC!ams, PowerShell/Agent.MOIS!tr, Backdoor.PS1.DINDOOR.SMTHA. JWT reveals campaignId: "6b357c4222050506", campaignName: "test", userId: "dea1196d5d4ab8d6", userNote: "Oko", proxies http://okobojirent.com — carrying the exact same customer userId and campaignId as commodity QuickAssist scams deployed elsewhere. Separately, terymar[.]com/install/Spf.ps1 delivers Tsundere Bot: Node.js with ethers@6.13.2, using EtherHiding C2 to query Ethereum contract 0x2B77671cfEE4D5EE6652E63bc9776A2EaFdbb7ee, resolving ws://185.236.25.119:3001. Additionally, lpu.dll (also known as QMAlgnkMX5.dll, hash d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc) is delivered via bitsadmin.exe and executed via rundll32.exe lpu.dll, main during active QuickAssist tech-support sessions, calling CredUIPromptForWindowsCredentialsW to write harvested credentials to C:\ProgramData\lopa.txt. The staging server rotated through terymar[.]com (Feb 5), wa.opt7dev[.]com (Feb 24 + Mar 3), and steuerberaterbarcelona[.]com (Mar 12); wa.opt7dev[.]com also hosted cv.msi, a fake-resume Tsundere Bot deployment node.

A.7 — Chain 7: Stagecomp/Darkcomp

Key finding: The only chain with a genuine (if uncitable) certificate link — and the same server hosting the "state espionage" loader concurrently hosted an amateur Coinbase crypto-drainer kit.

Vendors involved: Symantec [1], Check Point [3], Rapid7 [4], Unattributed researcher (Jan 2026)

Stagecomp loader ms_upd.exe (24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14) signed with the "Donald Gay" certificate (thumbprint B674578D4BDB24CD58BF2DC884EAA658B7AA250C), also observed as DIDS.exe (a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0). Downloads Darkcomp (Game.exe / WebView2.exe, hashes 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90 and 1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6) from moonzonet[.]com and uploadfiler[.]com. In Rapid7's telemetry, this same infrastructure deployed Chaos ransomware. Critically, ms_upd.exe was hosted on 172.86.126.208:443 — the exact same Cloudzy VPS server that concurrently ran a live-panel Coinbase/Ledger OTP-intercepting crypto-drainer kit (stats-coinbase[.]com, "tryanotherway" kit, logger.js).

A.8 — Chain 8: GCleaner/Amadey → CastleLoader/Smokest120

Key finding: The clearest proof of shared A/B testing infrastructure — Amadey Bot and DenoRAT fetch identical payloads from the same IP, and one payload is disguised as a JPEG image using a custom byte-sandwich technique.

Vendors involved: JUMPSEC [6], BitSight, Abuse.ch, vx-underground

GCleaner PPI distribution (campaign "mixeleven", Jan 12, 2026, delivered via Integrator_Portable.exe) tasks Amadey Bot v3.89 (C2 158.94.208[.]6/h8jfdmdWS/index.php, cc=RU). Amadey downloads secondary MSIs from sharecodepro[.]com — including MSI 13d2d0b4e4709d0f7705a7519ad099b10b0680ac6c40b96b74ee082ca4d93a6f (author "Mike62") and 85cd7a1e24ec449c9bf5f86ffccfa2fb8a684f240ae0e3b492839b4277e59080 (author "quebec_service65"), both flagged Trojan.Dindoor. A separate CastleLoader VBScript path drops Crypt1.ps1 from sharecodepro[.]com, which downloads both Petuhon.zip (a legitimate Python 3.9 Embed package — Russian slang "Петухон") and Smokest120.zip (obfuscated CastleRAT Build 120) from the same IP, 172.86.123.222 — direct evidence that Amadey Bot and DenoRAT execute identical PowerShell cradles for A/B testing across delivery vectors. The CastleRAT payload Smokest.jpg (3,823,807 bytes) is a custom byte-sandwich container: bytes 0–598,355 form a legitimate renderable JPEG ending at a genuine EOI marker (FF D9); bytes 598,357–3,823,805 contain the encrypted CastleRAT payload; a trailing fake EOI marker is appended so AV/EDR magic-byte validators classify the 3.82 MB file as a benign image. Unpacked process memory triggers the Yara signature for the same payload family, confirming a C2 at 23.94.145.120:9999.

A.9 — Chain 9: PsExec SEO

Key finding: Zero vendor threat report exists for this chain — it was flagged only by generic AV signatures, yet shares an identical decoy-filename technique with Chain 4.

Vendors involved: VirusTotal AV signatures only (no vendor report)

Fake PsExec installer archive drops PsExec.msi (576e998f55004774fb72164d791e10d9546d987f72f701ccdac8dc2e109c31a4, ~23 KB standard build), detected under generic Trojan.MuddyWater.10 / Backdoor.PS1.DINDOOR AV signatures. Drops the identical b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0 ("python85.ps1" decoy filename, zero actual Python code) seen in Chain 4, sharing the same campaignName: "test" and userId: dea1196d5d4ab8d6 — the recurrence of this exact decoy-filename payload across disparate lure campaigns supports commodity affiliate distribution rather than targeted nation-state activity.

A.10 — Chain 10: CyberProof Teams / update_ms

Key finding: A 48 MB MSI bundling its own Deno runtime to bypass web filters — attributed to Seedworm purely by inheriting Symantec's umbrella label, with no independent verification.

Vendors involved: CyberProof [5] ("Seedworm Teams Campaign", July 2026)

update_ms.msi (500ee77471669175b359bf57384291cab791200191d0e5a5bb190da53ccb30ee, 48.29 MB, author "Python78", subject "lima93", built via Linux msitools 0.106 on 2026-03-04, signed with the revoked "Anquesia Gray" certificate under Microsoft ID Verified CS EOC CA 01) bundles its own 122.7 MB deno.exe binary to bypass outbound deno.land web filter downloads. Establishes HKCU\Software\Microsoft\Windows\CurrentVersion\Run\alpha_client95 running wscript.exe Falcon_module63.vbstango13.ps1, binding TCP mutex 10091 and polling direct IP C2 http://140.82.18.48/health. JWT reveals buildId: "2bb76a4e96ee2312", buildNote: "123", buildType: "msi", userId: "eb97f1098d1fa9d8", userNote: "BrakeDigital". CyberProof's attribution to Seedworm relies entirely on Symantec's umbrella reporting, with no independently verified state-actor indicator.

Appendix B — Certificate Table

Field"Donald Gay""Amy Cherne""Anquesia Gray"
IssuerMicrosoft ID Verified CS AOC CA 02Microsoft ID Verified CS AOC CA 02Microsoft ID Verified CS EOC CA 01
ThumbprintB674578D4BDB24CD58BF2DC884EAA658B7AA250C0902D7915A19975817EC1CCB0F2F6714AED196386C841AF762A2D0234616BC1B8EB572BB3BC60944
Serial3300079A51C7063E66053D229B000000079A51330007F1068F41BF0F662A03B500000007F1063300073CFFF3E87A68E1439541000000073CFF
StatusRevoked (time-invalid)Revoked (time-invalid)Revoked by Issuer
SignsStagecomp, Darkcomp, Fakeset, DindoorFakeset, DindoorBundled-Deno CastleLoader (update_ms.msi)
Counter-evidenceFox Tempest MSaaS sells certs for $5k–$9k [9]SameSame

Certificates issued to Amy Cherne, Donald Gay, Anquesia Gray, Slims Software, and Zeebodem Agro were all issued under Microsoft Azure Trusted Signing. Criminal MSaaS vendor Fox Tempest sells these ID-verified Azure code-signing accounts, generated from mule identities, for $5k–$9k. Overlapping certificates prove only that affiliates bought accounts from the same underground sellers.

Appendix C — Full IOC Hash Table

SHA-256 HashTrue Forensic Classification & DescriptionReport Origin(s)
052e9951...883fPyArmor 9.1.9 Runtime Engine (pyarmor_runtime.pyd, 633,856 bytes)[6],[20]
067703b4...7094CastleLoader Deno Bootstrap VBScript (juliet_worker37.vbs, 933,377 bytes)[6],[20]
077ab28d...52dePython Dropper/Loader (Trojan.Fakeset, signed by Amy Cherne cert; C2 mofa****gas[.]info)[1],[2]
0bd1d24e...fdbaAmadey Bot (Donut-encrypted packed loader, "mixeleven" campaign)[6],[20]
0f9cf1cf...d542CastleLoader WiX MSI (1.08 MB, padded; Chain 3)[1],[2]
1319d474...f97b6Darkcomp PE RAT (Game.exe; C2 moonzonet[.]com; Chain 7)[1],[4]
13d2d0b4...4a93a6fCastleLoader WiX MSI (1be6c5708790fbc7.msi; Amadey task)[6],[20]
1fd01d13...4f02CastleRAT Stager Script (jam.ps1; downloads Petuhon.zip & Smokest120.zip)[6],[20]
24857fe8...4d14Stagecomp PE Loader (ms_upd.exe, "Donald Gay" cert; hosted with stats-coinbase[.]com)[1],[4]
29b777e7...062c8Tsundere Bot PowerShell Cradle (Spf.ps1; QuickAssist lures; Chain 6)[2],[14]
2a09bbb3...23a5CastleLoader WiX MSI (Serial.msi; Donald Gay cert; Chain 4)[1],[2],[14]
3dcb5e15...4354Amadey Bot Core Executable (C2 158.94.208[.]6)[6],[20]
4a2594b7...cfb2Tsundere Bot PowerShell Package (eagle_package6.ps1; VT 16/61; Chain 6)[14]
4ba0d3ae...c31CastleLoader NSIS Dropper (signed SERPENTINE SOLAR LIMITED; C2 maybedontbanplease[.]com)SOC/Analyst
500ee774...30eeBundled-Deno CastleLoader MSI (update_ms.msi, 48.29 MB; Chain 10)[5]
576e998f...31a4CastleLoader WiX MSI (PsExec.msi; SEO malvertising; Chain 8)AV Signatures
5f8347ee...136aStage 2 JavaScript RAT (polymorphic variant)[10],[17]
7467f326...ec4CastleLoader WiX MSI (Kilo52.msi; "Smokest" campaign; Chain 2)[1],[2],[10],[5],[19]
822ce21c...43b0CastleLoader WiX MSI (zclzgjjqewlzm1.msi; June 2026 build; Chain 5)[1],[17]
934a3c42...7f0aCastleRAT Build 120 Payload Archive (Smokest120.zip)[6],[20]
a92d28f1...ecc0Stagecomp PE Loader (DIDS.exe, "Donald Gay" cert; Chain 7)[1],[4],[2]
b0af82de...931a0CastleLoader Deno Bootstrap Script (python85.ps1; "test" campaign; Chains 4 & 8)[1],AV Sigs,[2]
bd8203ab...829aCastleLoader WiX MSI (clickzpaqkvba.msi; Chain 1)[1],[2],[10],[19]
c1e0a054...87a00NightshadeC2 Native Backdoor (Chain 5)[17]
d5879598...5ffcCommodity Credential Harvester (lpu.dll; Chain 6)[2],[14]
f6954b64...326d34Legitimate Python 3.9.5 Embed Package (Petuhon.zip)[6],[20]

Full 40+ entry hash table available on request; representative selection shown above covering all 10 chains.

Appendix D — Full Infrastructure Table

Indicator/ArtifactTrue Infrastructure Classification & FunctionReport Origin(s)
serialmenot[.]comCastleLoader / Stage 2 JS RAT C2 Server (primary Deno REST endpoint)[1],[2],[10],[5],[19]
zhivachkapro[.]comClixFlare ClickFix IAB Delivery Domain (Russian linguistic provenance)[2],[10]
terymar[.]comCommodity Staging Server (CastleLoader + Tsundere Bot; QuickAssist scams; Chain 6)[2],[14]
sharecodepro[.]comCommodity Payload Delivery Server (Amadey tasks)[6],[20]
moonzonet[.]comDarkcomp PE RAT C2 Server[1],[2],[4]
okobojirent[.]comDenoRAT / CastleLoader C2 Server[14],[19]
webstizkgao[.]comCastleLoader / DenoRAT C2 Server (server-compiled eval-loops; Chain 5)[17],[19]
gitempire.s3...backblazeb2[.]comCommodity Cloud Staging Bucket[1],[2]
elvenforest.s3...backblazeb2[.]comCommodity Cloud Staging Bucket[1],[2]
ws://185.236.25.119:3001Tsundere Bot WebSocket C2 Endpoint (via Ethereum smart contract)[14],[17]
0x2B77671cfEE4D5EE6652E63bc9776A2EaFdbb7eeEtherHiding Ethereum Smart Contract (blockchain C2 lookup)[14],[17]
172.86.123.222 / 23.94.145.120CastleRAT C2 IP Addresses[10],[6],[20]
158.94.208[.]6Amadey Bot C2 Server[6],[20]
194.38.20[.]224GCleaner PPI Distribution Server ("mixeleven" campaign)[6],[20]
172.86.126.208Stagecomp Hosting & C2 (co-located with stats-coinbase[.]com crypto-drainer)[4]
140.82.18.48CastleRAT C2 IP Address (Chain 10)[5]