Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators TwizAdmin -- Multi-Stage Crypto Clipper, Infostealer & Ransomware Operation

06299676b43749b8477c4bc977c09512957fc9b66fd5030c1874069632ce6092

TLP:CLEAR
Active

SHA-256 Hash

Description

A sophisticated multi-stage malware operation was identified through an exposed C2 panel at 103.241.66[.]238:1337, combining cryptocurrency clipboard hijacking across eight chains, BIP-39 seed phrase theft, browser credential exfiltration, ransomware module (crpx0), and Java RAT builder managed via FastAPI-based panel with license key system. The operation targets Windows and macOS using FedEx and OnlyFans-themed social engineering lures, with complete source code exposed in open directories. The ransomware component communicates with three Russian .ru domains resolving to 31.31.198[.]206 at REG.RU hosting, operating under the identity DataBreachPlus with Telegram, qTox, and ProtonMail contacts. Ten cryptocurrency wallet addresses spanning Bitcoin, Ethereum, Tron, Dogecoin, Litecoin, Solana, Ripple, and Bitcoin Cash were extracted from configurations, indicating a Malware-as-a-Service operation with tiered licensing.

Sightings (0)

No sightings recorded yet

Details

Name / Label
TwizAdmin -- Multi-Stage Crypto Clipper, Infostealer & Ransomware Operation
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:41
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 06299676b43749b8477c4bc977c09512957fc9b66fd5030c1874069632ce6092

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.