$100k in Crypto Drained by the Underground Operation

October 1, 2026

Netskope Threat Labs analyzed a crypto-stealing operation that drains victims’ cryptocurrency exchange accounts. An Aotera/Tedy loader injects a Vidar-class stealer into a Windows process, which then launches Chrome or Edge and injects its scripts into the pages the victim opens.

The operation is built with a malware builder whose loader telemetry records date back to October 2023. We refer to the builder as Underground, after the folder its loader logs to (C:\ProgramData\Underground\). For this operator, we mapped seven gate domains, 80+ destination addresses across about 23 chains, and roughly $100,000 in on-chain proceeds.

Infection chain: From lure archive to injected stealer

Figure 1: Overview of the infection chain and the operation.

The infection starts from a versioned lure archive, unencrypted 7z or zip files containing setup.exe, a trojanized msys-crypto-3.dll, and an encrypted data.bin. How the archives reach victims is not currently known.

The setup binary launches the Underground loader (stable_superior_verified.exe and sibling build easy_exceptional_instant.exe), which writes its log to C:\ProgramData\Underground\. The loader decrypts an embedded stage with per-build AES keys and uses section-based injection to place a self-decrypting payload into a suspended dllhost.exe process. The injected process then launches Chrome or Edge as child processes under the victim’s own browser profile, so the browser opens, already signed in to the victim’s accounts, and the stealer injects its scripts into those sessions. As a result, gate traffic originates from chrome.exe or msedge.exe, and the stealer stage is never written to disk as a file.

Figure 2: Sandbox process tree for the Underground loader. An injected dllhost.exe launches Chrome and Edge and stages stolen cookies under C:\ProgramData\Underground; a second dllhost.exe then deletes the folder.

Before it injects, the loader guards against analysis. It carries a hard-coded list of 67 process names and compares it against the running processes to detect an analysis or monitoring environment. The list covers debuggers and disassemblers (IDA, x64dbg, OllyDbg, dnSpy, Cutter, radare2), instrumentation frameworks (Frida, Pin), network sniffers (Wireshark, Fiddler, Charles, Burp Suite), process monitors (Process Monitor, Process Explorer, Process Hacker, PEStudio), and virtual-machine and sandbox agents (VMware, VirtualBox, QEMU guest tools).

ida64.exe|idag.exe|idaq.exe|idaw.exe|x32dbg.exe|x64dbg.exe|ollydbg.exe
immunitydebugger.exe|dnspy.exe|ilspy.exe|cutter.exe|r2.exe|frida.exe
frida-server.exe|frida-inject.exe|wireshark.exe|dumpcap.exe|tcpdump.exe
fiddler.exe|charles.exe|burpsuite.exe|procmon.exe|procexp.exe
processhacker.exe|pestudio.exe|vmtoolsd.exe|vboxservice.exe|qemu-ga.exe

Figure 3: Part of the loader’s hard-coded anti-analysis list (28 of 67 process names shown).

The Underground loader belongs to the Aotera/Tedy family, a class of Windows loaders that unpack and inject a later stage rather than steal data themselves. The injected payload is a Vidar-class stealer, as it matches Vidar on capability, collecting Chromium and Gecko cookies and passwords, Discord and Telegram data, desktop and extension wallets, and screenshots. However, it differs on command and control, where instead of employing Vidar’s classic dead-drop configuration (such as a social-media profile), it uses the custom /api/machine/* protocol to reach one hardcoded gate (e.g. quick-neo[.]com).

Antivirus labels differ across vendors and builds; verdicts may contain the labels: Rhadamanthys, LummaStealer or Tedy. Our analysis of the samples shows the Aotera/Tedy loader and Vidar-class payload described here.

The /api/machine gate protocol

Each infected machine polls its assigned gate at /api/machine/commands, identified by a per-machine UUID. The gate is an nginx/FastCGI origin behind Cloudflare. Its root returns a 404 and only the /api/machine/* paths respond as to avoid scanners.

A request to /api/machine/injections with the machine’s UUID returns the operator’s full configuration. This is a 9 MB JSON array of browser-injection scripts for more than 15 exchange and web targets, together with the clipboard-clipper rules and file-finder logic.

Figure 4: The gate root returns a 404 page, while /api/machine/injections returns the operator’s configuration, a 9 MB JSON array of obfuscated injection scripts (responses captured 2026-09-22).

The operator rotates gate domains. We tracked seven (listed in the indicators section), first seen in our telemetry between November 2025 and June 2026. Some sat registered for over a year before use; true-lie[.]com was registered in June 2024 but first seen in November 2025. Others went into use within days; slow-sky[.]com appeared in our telemetry three days after registration and was classified as a malicious site about three months later. Each new domain therefore operates for a period before reputation-based blocking applies to it. slow-sky[.]com was live and serving the full configuration as of the time of this investigation.

Automated account drain and clipboard clipper

The injection configuration automatically drains the victim’s exchange account. Within a logged-in Binance session, the injected script renders a fake security-verification dialog as an in-page overlay drawn over the page content, rather than as a separate window, and styles it to mimic Binance’s own two-factor prompt, localized into about 25 languages.

Figure 5: The fake security-verification overlay displayed over a logged-in Binance session.

Behind the overlay, it disables the withdrawal allow list, converts balances to Bitcoin through Binance’s private API paths, and withdraws the funds to an 11-address Bitcoin reserve pool. A webmail injection covering Gmail, Outlook, Yahoo, and Proton then watches for the exchange’s withdrawal confirmation, using keywords in about 24 languages, and rewrites its subject and body in the victim’s browser so it reads as a routine message.

Victim logged in to BinanceFake 'security verification' overlay
(~25 languages) occupies the victimDisable the withdrawal allow listRead the 24-hour withdrawal limitsCancel open orders, grid and Earn positions;
convert balances to USDC, then to BTC
(90-100% by balance size)Withdraw to one of 11 Bitcoin
reserve-pool addressesReport each step to the operator's
C2 log (easybooters[.]com)

Figure 6: The automated Binance account-drain sequence, run inside the victim’s own authenticated session and reconstructed from the deobfuscated injection configuration.

The drain parameters are set in the served configuration. It converts holdings to USDC and then Bitcoin, taking the full balance on small accounts and 90% on larger ones, and reports each step to the operator’s log endpoint.

// Binance drain configuration (deobfuscated)
transfer: {
  percentBelowThreshold: '1',    // take 100% of small balances
  percentAboveThreshold: '0.9'   // take 90% of large balances
}
trade: {
  intermediateTicker: 'USDC',    // convert holdings to USDC
  baseTicker: 'BTC'              // then to BTC for withdrawal
}
logEndpoint: 'https://easybooters.com/newlog.php'  // report every step

Figure 7: Excerpt of the deobfuscated Binance drain configuration: the portfolio-conversion thresholds and the operator’s command-and-control log endpoint.

The payload also includes a clipboard clipper with 32 rules covering about two dozen coins. When the victim copies a wallet address, the clipper replaces it with an operator address. The served configuration holds more than 80 destination addresses across about two dozen chains. Every gate we reached served the same address set. The wallets remained in use during our September 2026 checks. One clipper Bitcoin address (bc1qwenpr55ekcs3a46ly4hqkjn652sppttdnsszhd) received eight new inbound transactions and had not been swept, and an Ethereum clipper address (0x4cC35bE54c358146E7b71E58f965532193848FDd) received new deposits in the same period.

[
  {"name":"BTC","reg":"^1[a-zA-HJ-NP-Z0-9]{25,39}$","value":"19hdEPSFQ4iUhtWoXHqg2E1kPCpUmaEgP8"},
  {"name":"BTC","reg":"^3[a-zA-HJ-NP-Z0-9]{25,39}$","value":"3H4ZCi9mhZsFpowmmVhUh1NF1C5NoSPPvH"},
  {"name":"BTC","reg":"^[bB][cC]1[pP][a-zA-Z0-9]{38,58}$","value":"bc1pfpwq9kd30e2hd2x2p90j302c9vtnnh5ejhw4vw46jc92rjtn259qlnv8wc"},
  {"name":"BTC","reg":"^bc1[a-zA-HJ-NP-Z0-9]{25,39}$","value":"bc1qwenpr55ekcs3a46ly4hqkjn652sppttdnsszhd"},
  {"name":"LTC","reg":"^L[a-zA-HJ-NP-Z0-9]{26,41}$","value":"LXnj7XNxmRkTnEbdDzKd7QfZSGaEriFu4m"}
]

Figure 8: Excerpt of the clipper rules served by the gate. When a copied string matches a wallet-address pattern, the clipper replaces it with the operator’s address.

On-chain proceeds and victim count

We estimate this operator’s lifetime proceeds at roughly $100,000 in on-chain value. This is a conservative figure. It sums inbound transactions to the destination addresses at spot prices and stops at the first hop. Past that, the operator works to obscure the trail, seeding decoy transactions with fabricated lookalike tokens that imitate real stablecoins and commingling proceeds with unrelated funds, so downstream cash-out flows cannot be reliably attributed to the campaign and are excluded. Most receipts are small (the mean is about $82), but individual drains reach much higher: one Bitcoin address received about $18,800, most of it in a single 0.21 BTC deposit.

Figure 9: Single on-chain drain to one of the operator’s Bitcoin addresses.

On-chain deposits show at least 350 to 430 paying victims, counted as unique sending addresses after filtering out contracts and services. Funds taken from exchange accounts arrive from the exchange’s own wallets and are not counted, so the true number is higher. Drains were still arriving at the time of writing.

Figure 10: Balance history of one of the operator’s clipper Bitcoin addresses, rising with new deposits through September 2026 (mempool.space, captured 2026-09-29).

The Underground builder

Underground loader reports each stage to a telemetry panel at 95.164.53[.]76 (for example “startCrypt”, then “startLoader” and “success”) under /new/log/<build ID>/. The panel holds records from October 2023 to January 2026.

hxxp://95.164.53[.]76/new/log/048466C5/startCrypt
hxxp://95.164.53[.]76/new/log/8320e1a4/startloader/1767499038
hxxp://95.164.53[.]76/new/log/8320E1A4/success/1767499039
hxxp://95.164.53[.]76/new/log/29A5FDA7/startLoader/1769331211
hxxp://95.164.53[.]76/new/log/29A5FDA7/failed/1769331221
hxxp://95.164.53[.]76/new/log/D9D278DD/success/1696492954

Figure 11: Loader telemetry URLs recorded by VirusTotal sandboxes. Each loader stage reports to /new/log/<build ID>/<stage>/<Unix timestamp>.

We do not attribute this operation to a named actor. The builder has no consistent product name, and Underground is our label for it. The loader’s file metadata is randomized per build.

Netskope

Netskope Threat Protection detects this campaign at three layers.

  • Behavioral network signature, Emerging Threats community (“ET MALWARE Unknown Info Stealer URI Structure”), which matches the /api/machine/* URI structure regardless of domain.
  • Malicious-site classification, which blocks gate domains once they are classified.
  • Scanning and blocking binaries/loader builds.

Recommendations for defenders

  • Treat a blocked gate as an active infection. Infected machines kept polling a blocked gate for months, waiting for the operator’s next domain. A web block stops the traffic but does not remove the implant. Check endpoints for injection into dllhost.exe, Chrome or Edge launched by dllhost.exe, files written to and deleted from C:\ProgramData\Underground\ (the malware removes the folder after use, so its absence does not mean the host is clean), and the PNG-named artifacts in AppData\Local.
  • Use behavioral URI detection alongside domain reputation. The operator rotates domains faster than reputation-based classification can follow. Hunt for chrome.exe or msedge.exe requests to /api/machine/* paths on any domain.
  • Verify exchange withdrawals through a separate channel. The payload can rewrite confirmation emails as they display in webmail, so an inbox notice alone does not confirm a transaction.

Conclusions

This operation combines the Underground builder, rotating Cloudflare-fronted gates, and a payload that drains exchange accounts and disguises the confirmation email in webmail. Netskope Threat Protection detects the gate traffic and both loader builds. Organizations should also remediate endpoints that contact a gate, because blocking the gate does not remove the implant.

Disclosure

We disclosed the live gate domains to Cloudflare. As Cloudflare notes, “Because Cloudflare does not have the ability to remove content from a website, it is our practice to forward abuse complaints to entities like the hosting provider and/or website owner to follow up.” Because that process notifies parties tied to the infrastructure, the operator may move to new infrastructure, so the listed domains may change. The behavioral detections above are designed to hold across such changes.

Indicators of compromise

The full list of indicators for this campaign is published in the Netskope Threat Labs IOC repository.

author image

Vini Egerland

Vini is a CISSP-certified threat researcher at Netskope Threat Labs, where he focuses on the security implications of emerging technologies, supply chain compromise, and post-compromise tactics.
Vini is a CISSP-certified threat researcher at Netskope Threat Labs, where he focuses on the security implications of emerging technologies, supply chain compromise, and post-compromise tactics.
Keep a close eye on The Lens