Netskope Threat Labs uncovered the Underground builder, an Aotera/Tedy-based operation that injects a Vidar-class stealer into Windows processes and uses browser-session injection to drain cryptocurrency exchange accounts. The campaign rotates Cloudflare-fronted gates, abuses Chrome or Edge sessions, and has generated about $100,000 in on-chain proceeds from at least 350 to 430 victims. #Underground #Aotera #Tedy #Vidar #Binance #Cloudflare
Keypoints
- The infection starts from versioned lure archives containing setup.exe, a trojanized msys-crypto-3.dll, and encrypted data.bin.
- The Underground loader injects a self-decrypting payload into suspended dllhost.exe, then launches Chrome or Edge under the victimâs browser profile.
- The payload is a Vidar-class stealer that collects cookies, passwords, Discord and Telegram data, wallet data, and screenshots.
- The campaign uses a custom /api/machine/* command-and-control protocol and rotating gate domains behind Cloudflare rather than Vidarâs usual dead-drop C2.
- The injected script performs automated Binance account draining by disabling withdrawal protections, converting balances to BTC, and withdrawing to operator-controlled reserve addresses.
- A clipboard clipper replaces copied wallet addresses with attacker addresses across many cryptocurrencies and chains.
- Researchers estimate roughly $100,000 in on-chain proceeds and at least 350 to 430 paying victims, with activity continuing through September 2026.
MITRE Techniques
- [T1055 ] Process Injection â The loader injects a self-decrypting payload into a suspended process and later injects scripts into browser sessions (âuses section-based injection to place a self-decrypting payload into a suspended dllhost.exe processâ; âinjects its scripts into those sessionsâ)
- [T1204 ] User Execution â The infection begins when the victim opens a lure archive that contains the setup binary (âThe infection starts from a versioned lure archive, unencrypted 7z or zip files containing setup.exeâ)
- [T1105 ] Ingress Tool Transfer â The setup binary launches the loader and stages the malware components from the archive (âThe setup binary launches the Underground loaderâ; âcontains setup.exe, a trojanized msys-crypto-3.dll, and an encrypted data.binâ)
- [T1562.001 ] Impair Defenses: Disable or Modify Tools â The stealer disables withdrawal allow lists before draining the account (âit disables the withdrawal allow listâ)
- [T1082 ] System Information Discovery â The loader checks running processes to detect analysis and monitoring environments (âcompares it against the running processes to detect an analysis or monitoring environmentâ)
- [T1057 ] Process Discovery â The loader enumerates running processes and matches them against a hard-coded list (âcompares it against the running processesâ)
- [T1497.001 ] Virtualization/Sandbox Evasion: System Checks â The anti-analysis list includes VM and sandbox tools to avoid execution in analysis environments (âvirtual-machine and sandbox agents (VMware, VirtualBox, QEMU guest tools)â)
- [T1518.001 ] Software Discovery: Security Software Discovery â The loader checks for debugging, monitoring, and network-analysis tools such as IDA, Wireshark, and Process Explorer (âcovers debuggers and disassemblers ⌠network sniffers ⌠process monitorsâ)
- [T1056.001 ] Input Capture: Keylogging â The clipper and webmail injection intercept user-entered or displayed sensitive payment and confirmation data in-browser (ârewrites its subject and bodyâ; âwhen the victim copies a wallet address, the clipper replaces itâ)
- [T1119 ] Automated Collection â The stealer automatically collects browser cookies, passwords, wallets, and screenshots (âcollecting Chromium and Gecko cookies and passwords ⌠desktop and extension wallets, and screenshotsâ)
- [T1021 ] Remote Services â The payload operates within authenticated browser sessions on the victimâs machine to interact with online services (âlaunches Chrome or Edge ⌠under the victimâs own browser profileâ)
Indicators of Compromise
- [Domains ] gate infrastructure and log endpoint â quick-neo[.]com, slow-sky[.]com, true-lie[.]com, easybooters[.]com
- [IP address ] loader telemetry / builder panel â 95.164.53[.]76
- [File names ] lure and loader artifacts â setup.exe, msys-crypto-3.dll, data.bin, stable_superior_verified.exe, easy_exceptional_instant.exe
- [Directories ] loader logs and temporary artifacts â C:ProgramDataUnderground, AppDataLocal
- [URLs / paths ] C2 and telemetry endpoints â /api/machine/commands, /api/machine/injections, /new/log//, /new/log///
- [Wallet addresses ] clipper and reserve-pool destinations â bc1qwenpr55ekcs3a46ly4hqkjn652sppttdnsszhd, 0x4cC35bE54c358146E7b71E58f965532193848FDd, and other destination addresses
- [Bitcoin addresses ] operator destinations and replacement values â 19hdEPSFQ4iUhtWoXHqg2E1kPCpUmaEgP8, 3H4ZCi9mhZsFpowmmVhUh1NF1C5NoSPPvH, bc1pfpwq9kd30e2hd2x2p90j302c9vtnnh5ejhw4vw46jc92rjtn259qlnv8wc
- [Litecoin address ] clipper replacement value â LXnj7XNxmRkTnEbdDzKd7QfZSGaEriFu4m
Read more: https://www.netskope.com/blog/100k-in-crypto-drained-by-the-underground-operation