Researchers reported an active malware supply-chain campaign distributing trojanized Windows installers that abuse DLL sideloading to launch STX RAT in memory through a malicious CRYPTBASE.dll. Confirmed lures included fake packages for CPU-Z, X-VPN, Binance, MEXC, Bybit, Exodus, MetaTrader 5, and a Steam-themed decoy, with infrastructure tied to supp0v3[.]com and an actor tracked as Leda Elacoate. In the X-VPN case, investigators said the vendor's official channels were not compromised; only users who downloaded the repackaged installer from attacker-controlled sources were exposed. X-VPN later released Windows version 77.5.3 with hardening changes after disclosure of the DLL search-order weakness.
Incident analysis of the CPU-Z lure showed the intrusion extending well beyond initial access. After STX RAT execution, the operator deployed PureLogs Stealer for credential theft and PureHVNC via InstallUtil.exe, then staged prolonged data theft using rclone tunneled through a hidden QEMU Alpine virtual machine acting as a proxy. The observed operation lasted about five days and included roughly 54 hours of continuous exfiltration to 94.156.119[.]71:443, illustrating a coordinated crimeware workflow that combined fake software distribution, remote access, credential harvesting, and covert exfiltration.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers described an active supply-chain campaign in which a threat actor using the alias Leda Elacoate distributed trojanized installers that sideloaded a malicious CRYPTBASE.dll to deploy STX RAT in memory. The campaign began with fake cryptocurrency-related packages and later expanded to additional lures including Steam-themed and X-VPN bundles.
X-VPN released Windows version 77.5.3 with multiple hardening measures in response to the disclosed DLL sideloading issue. According to the report, only users who downloaded the trojanized installer from the attacker's channel were at risk.
Howler Cell reported the X-VPN Windows client DLL sideloading weakness to X-VPN. The issue enabled a repackaged installer to load a malicious CRYPTBASE.dll, though X-VPN said its official service and distribution channels were not breached.
A deception environment observed a multi-stage intrusion beginning with a trojanized CPU-Z 2.19 ZIP that side-loaded a malicious CRYPTBASE.dll to launch STXRAT. The attack progressed to PureLogs Stealer, PureHVNC via InstallUtil.exe, and roughly 54 hours of data exfiltration through rclone routed via a hidden QEMU Alpine VM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
hybrid-analysis.blogspot.com
Open sourcecyderes.com
Open sourceblog.deception.pro
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.