Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators TwizAdmin -- Multi-Stage Crypto Clipper, Infostealer & Ransomware Operation

584796212f99efc7ac765d6048913fe34e46a64b13a8a78fb3a465b8c61f3527

TLP:CLEAR
Active

SHA-256 Hash

Description

A sophisticated multi-stage malware operation was identified through an exposed C2 panel at 103.241.66[.]238:1337, combining cryptocurrency clipboard hijacking across eight chains, BIP-39 seed phrase theft, browser credential exfiltration, ransomware module (crpx0), and Java RAT builder managed via FastAPI-based panel with license key system. The operation targets Windows and macOS using FedEx and OnlyFans-themed social engineering lures, with complete source code exposed in open directories. The ransomware component communicates with three Russian .ru domains resolving to 31.31.198[.]206 at REG.RU hosting, operating under the identity DataBreachPlus with Telegram, qTox, and ProtonMail contacts. Ten cryptocurrency wallet addresses spanning Bitcoin, Ethereum, Tron, Dogecoin, Litecoin, Solana, Ripple, and Bitcoin Cash were extracted from configurations, indicating a Malware-as-a-Service operation with tiered licensing.

Sightings (0)

No sightings recorded yet

Details

Name / Label
TwizAdmin -- Multi-Stage Crypto Clipper, Infostealer & Ransomware Operation
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:41
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 584796212f99efc7ac765d6048913fe34e46a64b13a8a78fb3a465b8c61f3527

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.