UtilifySetup.exe is an Electron-based infostealer/data-stealing Trojan observed in 2026 as a payload in campaigns exploiting Ghost CMS vulnerability CVE-2026-26980. In the reported attack chain, attackers used the Ghost CMS SQL injection flaw to steal admin API keys, inject malicious JavaScript into compromised websites, and present selected visitors with fake Cloudflare/ClickFix prompts that tricked them into executing commands on Windows systems. Those commands led to delivery of malware including DLL loaders, JavaScript droppers, and UtilifySetup.exe. The malware is described as targeting infected Windows systems and stealing session tokens, browser credentials, and other authentication material. Multiple reports state that UtilifySetup.exe is Electron-based, establishes persistence, and contacts command-and-control infrastructure every 30 seconds to retrieve commands; one report identifies the C2 as web-telegram[.]ug. It is also described as a modified version of the open-source Grape client. High-confidence associated context includes use in broad website-compromise campaigns affecting more than 700 Ghost CMS sites across sectors such as universities, media, SaaS, fintech, and security-related sites. Known indicators directly mentioned in the content include the filename UtilifySetup.exe and network communication with web-telegram[.]ug.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Уязвимость CVE-2026-26980 затрагивает версии Ghost CMS с 3.24.0 по 6.19.0 включительно. Исправлена в 6.19.1. Значение slug из параметра запроса подставлялось напрямую в SQL-конструкцию ORDER BY через конкатенацию строк вместо параметризованного binding. Эксплуатация не требует ни учётных данных, ни предварительной разведки — достаточно одного crafted HTTP-запроса к публичному endpoint. Атакующий отправляет запрос с blind SQLi payload в параметре slug/order и посимвольно извлекает произвольные данные из БД. Главная цель — Admin API Key. | Electron-based infostealer ( UtilifySetup.exe ) - сбор сессионных токенов, credential из браузеров и аутентификационного материала с заражённых Windows-систем.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Visitors who pass a fingerprinting verification are presented with a fake Cloudflare prompt, leading them to execute a command that installs malware...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Electron-based infostealer used as the final payload in the ClickFix chain; it steals session tokens, browser credentials, and other authentication material from infected Windows systems.
Electron-based malware described as a modified version of the open-source Grape client. It establishes persistence on the victim system and beacons to a command-and-control server every 30 seconds to receive new commands.
A malicious program delivered via ClickFix-style social engineering after compromise of Ghost CMS sites; it appears to be part of the payload chain used to install malware on victim systems.
UtilifySetup.exe is an Electron-based data-stealing trojan used as the final payload. It establishes persistence and beacons to a command-and-control server every 30 seconds.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.