{"data":[{"id":"8a007729-bde5-453c-bbfc-0466418e9d19","created_at":"2026-09-19T02:02:37.535491Z","updated_at":"2026-09-20T02:02:32.808318Z","deleted_at":null,"sha1_hash":"5a87fd0ebfeafd69b0a65ac9cabc8bbe7a32f02b","title":"Hackers claim breach of Russian election systems days before parliamentary vote","llm_title":"","authors":"","file_creation_date":"0001-01-01T00:00:00Z","file_modification_date":"0001-01-01T00:00:00Z","file_size":78265,"plain_text":"https://therecord.media/russia-election-hackers-breach\n\nHackers claim breach of Russian election systems days before\n\nparliamentary vote\n\nBy Daryna Antoniuk\n\nPublished: 2026-09-17 · Archived: 2026-09-19 02:00:19 UTC\n\nAn anonymous hacking group claimed to have broken into computer systems connected to Russia’s election\n\ninfrastructure just days before the country begins voting for a new parliament.\n\nThe group, calling itself CikLeak, said it gained access to systems belonging to Russia’s Central Election\n\nCommission and companies involved in developing Vybory, the state-run platform used to administer elections.\n\nThe hackers claimed to have stolen internal documents, server configurations, passwords and employee\n\ncommunications from the commission and its contractors, including Russian telecom giant Rostelecom.\n\nThey provided the stolen material to Important Stories, an independent Russian investigative outlet that said it had\n\nauthenticated the documents. However, it remains unclear how deeply the hackers penetrated the election\n\ninfrastructure or whether they gained access to systems directly involved in voting or counting ballots.\n\n“We infiltrated the infrastructure of Russia’s Central Election Commission and downloaded secret documents and\n\ndevelopers’ internal chats,” the group claimed on its website.\n\nCikLeak said it did not intend to disrupt voting or interfere with the work of election commissions. Instead, the\n\ngroup said its goal was to expose how the Russian electoral system works internally and what it described as\n\nopportunities for authorities to manipulate election results.\n\nThe hackers also published screenshots purportedly showing compromised systems and urged Russians to vote in\n\nperson on the final day of the election, arguing that doing so would make manipulation more difficult.\n\nRussia will hold elections for all 450 seats in the State Duma, the lower house of parliament, over three days\n\nbeginning Friday. It will be the first election for the chamber since Russia launched its full-scale invasion of\n\nUkraine in February 2022.\n\nThe vote will also be the first federal election conducted using the Vybory 2.0 platform. Use of the system began\n\nthis year, replacing an earlier version that had been used since the late 1990s.\n\nRussia’s Central Election Commission (CEC) had warned of growing cyber threats as voting approached.\n\nA day before CikLeak disclosed the alleged breach, Russian election officials tested the security of the Vybory\n\nportal, remote electronic voting system and video surveillance infrastructure. The assessment identified the video\n\nsurveillance system, particularly the uninterrupted transmission of its feeds, as a “weak link.”\n\nCEC Chair Ella Pamfilova said the number of attacks targeting election systems and related infrastructure had\n\nbeen rising ahead of the vote.\n\nPage 1 of 3\n\nhttps://therecord.media/russia-election-hackers-breach\n\n“We have been dealing with this for years, but what is happening now is difficult to compare with anything in\n\nterms of the intensity, volume and speed of the various attacks,” Pamfilova said.\n\nHer comments followed assurances in August that the election system was fully protected against cyberattacks.\n\nPamfilova said information about eligible voters was updated online twice a year and stored in a closed-access\n\nsystem.\n\nRussian election infrastructure has been targeted during previous votes.\n\nDuring the March 2024 presidential election, hackers launched distributed denial-of-service attacks and set up\n\nphishing sites and fake Telegram channels designed to imitate official Russian services.\n\nRostelecom said at the time that most attacks against election infrastructure originated from Ukraine, Western\n\nEurope and North America and involved what it described as professional hacking groups.\n\nHackers also targeted online services belonging to United Russia, President Vladimir Putin’s political party, as\n\nwell as government services in several Russian regions.\n\nUkraine’s military intelligence agency, known as HUR, later acknowledged that it was behind attacks on United\n\nRussia and Russia’s electronic voting system.\n\nNo previous article\n\nNo new articles\n\nPage 2 of 3\n\nhttps://therecord.media/russia-election-hackers-breach\n\nDaryna Antoniuk\n\nis a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in\n\nEastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for\n\nForbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.\n\nSource: https://therecord.media/russia-election-hackers-breach\n\nPage 3 of 3","extraction_quality":1,"language":"EN","sources":["MISPGALAXY"],"origins":["web"],"references":["https://therecord.media/russia-election-hackers-breach"],"report_names":["russia-election-hackers-breach"],"threat_actors":[{"id":"b0078986-446f-4613-b4c7-dd68aad3d62c","created_at":"2026-09-19T02:00:05.60724Z","updated_at":"2026-09-20T02:00:06.002416Z","deleted_at":null,"main_name":"CikLeak","aliases":[],"source_name":"MISPGALAXY:CikLeak","tools":[],"source_id":"MISPGALAXY","reports":null}],"ts_created_at":1789783357,"ts_updated_at":1789869752,"ts_creation_date":0,"ts_modification_date":0,"files":{"pdf":"https://archive.orkl.eu/5a87fd0ebfeafd69b0a65ac9cabc8bbe7a32f02b.pdf","text":"https://archive.orkl.eu/5a87fd0ebfeafd69b0a65ac9cabc8bbe7a32f02b.txt","img":"https://archive.orkl.eu/5a87fd0ebfeafd69b0a65ac9cabc8bbe7a32f02b.jpg"}},{"id":"8eb49913-fb71-422f-a5ee-c54bbdb3bdfb","created_at":"2026-09-19T02:02:36.484528Z","updated_at":"2026-09-20T02:01:58.164495Z","deleted_at":null,"sha1_hash":"e557448d4f67e12c6427dd89258b166a91b04ba7","title":"UAC-0056 cyberattack on Ukrainian authorities using GraphSteel and GrimPlant malware","llm_title":"","authors":"CERT_UA","file_creation_date":"2022-04-01T13:59:56Z","file_modification_date":"2022-04-01T13:59:56Z","file_size":1443077,"plain_text":"CERT-UA\n\ncert.gov.ua/article/38374\n\ngeneral information\n\nThe Governmental Computer Emergency Response Team of Ukraine CERT-UA received\n\ninformation on the distribution of e-mails on the topic \"Wage arrears\" among government\n\nagencies of Ukraine. Attached to the letter is the document \"Wage arrears.xls\", which\n\ncontains legitimate statistics and macros. At the same time, hex-coded data has been added\n\nto the mentioned document as an attachment. The macro, after activation, will decode the\n\ndata, create the EXE-file \"Base-Update.exe\" on the computer and execute it.\n\nThis file is a downloader developed using the GoLang programming language. The program\n\nwill download and run another bootloader, which, in turn, will download and run malware\n\nGraphSteel and GrimPlant on your computer.\n\nThe detected activity is associated with the activity of the group UAC-0056.\n\nIndicators of compromise\n\nFiles:\n\nda305627acf63792acb02afaf83d94d1 \nc1afb561cd5363ac5826ce7a72f0055b400b86bd7524da43474c94bc480d7eff Wage arrears.xls \n06124da5b4d6ef31dbfd7a6094fc52a6 \n9e9fa8b3b0a59762b429853a36674608df1fa7d7f7140c8fccd7c1946070995a Base-Update.exe \n(GoDownloader) \n36ff9ec87c458d6d76b2afbd5120dfae \n8ffe7f2eeb0cbfbe158b77bbff3e0055d2ef7138f481b4fac8ade6bfb9b2b0a1 java-sdk.exe \n(GoDownloader) \n4a5de4784a6005aa8a19fb0889f1947a \n99a2b79a4231806d4979aa017ff7e8b804d32bfe9dcc0958d403dfe06bdd0532 oracle-java.exe \n(GrimPlant) \n6b413beb61e46241481f556bb5cdb69c \nc83d8b36402639ea3f1ad5d48edc1a22005923aee1c1826afabe27cb3989baa3 microsoft-\ncortana.exe (GraphSteel) (2022-03-20)\n\nNetwork:\n\nhxxp: // 194 [.] 31.98.124: 443 / i \nhxxp: // 194 [.] 31.98.124: 443 / p \nhxxp: // 194 [.] 31.98.124: 443 / m \nws: // 194 [.] 31.98.124: 443 / c \n194 [.] 31.98.124\n\n1/2\n\nHosts:\n\n% TMP% \\ Base-Update.exe \n% USERPROFILE% \\. Java-sdk \\ java-sdk.exe \n% USERPROFILE% \\. Java-sdk \\ oracle-java.exe \n% USERPROFILE% \\. Java-sdk \\ microsoft-cortana.exe\n\nGraphic images\n\n2/2","extraction_quality":1,"language":"EN","sources":["APTnotes"],"origins":["web"],"references":["https://app.box.com/s/s9jqmfj3eqvzuvbmap8tj673tj37giqd"],"report_names":["cert.gov.ua-CERT-UA-4293(03-28-2022)"],"threat_actors":[{"id":"eecf54a2-2deb-41e5-9857-fed94a53f858","created_at":"2023-01-06T13:46:39.349959Z","updated_at":"2026-09-20T02:00:04.358926Z","deleted_at":null,"main_name":"SaintBear","aliases":["TA471","Storm-0587","DEV-0587","Lorec Bear","Bleeding Bear","Cadet Blizzard","UNC2589","UAC-0056","Nascent Ursa","Nodaria","FROZENVISTA","Saint Bear","Lorec53","EMBER BEAR"],"source_name":"MISPGALAXY:SaintBear","tools":[],"source_id":"MISPGALAXY","reports":null},{"id":"c28760b2-5ec6-42ad-852f-be00372a7ce4","created_at":"2022-10-27T08:27:13.172734Z","updated_at":"2026-09-20T02:00:04.219756Z","deleted_at":null,"main_name":"Ember Bear","aliases":["Ember Bear","UNC2589","Bleeding Bear","DEV-0586","Cadet Blizzard","Frozenvista","UAC-0056"],"source_name":"MITRE:Ember Bear","tools":["P.A.S. Webshell","CrackMapExec","ngrok","reGeorg","WhisperGate","Saint Bot","PsExec","Rclone","Impacket"],"source_id":"MITRE","reports":null},{"id":"03a6f362-cbab-4ce9-925d-306b8c937bf1","created_at":"2024-11-01T02:00:52.635907Z","updated_at":"2026-09-20T02:00:04.120356Z","deleted_at":null,"main_name":"Saint Bear","aliases":["Saint Bear","Storm-0587","TA471","UAC-0056","Lorec53"],"source_name":"MITRE:Saint Bear","tools":["OutSteel","Saint Bot"],"source_id":"MITRE","reports":null},{"id":"083d63b2-3eee-42a8-b1bd-54e657a229e8","created_at":"2022-10-25T16:07:24.143338Z","updated_at":"2026-09-20T02:00:06.338062Z","deleted_at":null,"main_name":"SaintBear","aliases":["Ember Bear","FROZENVISTA","G1003","Lorec53","Nascent Ursa","Nodaria","SaintBear","Storm-0587","TA471","UAC-0056","UNC2589"],"source_name":"ETDA:SaintBear","tools":["Agentemis","Cobalt Strike","CobaltStrike","Elephant Client","Elephant Implant","GraphSteel","Graphiron","GrimPlant","OutSteel","Saint Bot","SaintBot","cobeacon"],"source_id":"ETDA","reports":null}],"ts_created_at":1789783356,"ts_updated_at":1789869718,"ts_creation_date":1648821596,"ts_modification_date":1648821596,"files":{"pdf":"https://archive.orkl.eu/e557448d4f67e12c6427dd89258b166a91b04ba7.pdf","text":"https://archive.orkl.eu/e557448d4f67e12c6427dd89258b166a91b04ba7.txt","img":"https://archive.orkl.eu/e557448d4f67e12c6427dd89258b166a91b04ba7.jpg"}},{"id":"767e4c60-e72b-4205-9944-4ec35f69dffd","created_at":"2026-09-19T02:02:02.065404Z","updated_at":"2026-09-20T02:01:59.61425Z","deleted_at":null,"sha1_hash":"39e53915de468512258066c3ae2875770bd68c45","title":"Inexsmar: An unusual DarkHotel campaig","llm_title":"","authors":"Bitdefender","file_creation_date":"2017-07-18T15:29:48Z","file_modification_date":"2017-07-18T15:30:03Z","file_size":8946977,"plain_text":"Bitdefender is a global security technology company that delivers solutions in more than 100 countries through a network of value-added alliances, distributors\n\nand reseller partners. Since 2001, Bitdefender has consistently produced award-winning business and consumer security technology, and is a leading security\n\nprovider in virtualization and cloud technologies. Through R\u0026D, alliances and partnership teams, Bitdefender has elevated the highest standards of security\n\nexcellence in both its number-one-ranked technology and its strategic alliances with the world’s leading virtualization and cloud technology providers. More\n\ninformation is available at\n\nhttp://www.bitdefender.com/\n\nAll Rights Reserved. © 2015 Bitdefender. All trademarks, trade names, and products referenced herein are property of their respective owners.  \nFOR MORE INFORMATION VISIT: enterprise.bitdefender.com\n\ncrea1572\nBD-Business-Jul.18.2017-Tk#:","extraction_quality":1,"language":"EN","sources":["CyberMonitor","APTnotes"],"origins":["","web"],"references":["https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections/raw/master/2017/2017.07.18.Inexsmar/Bitdefender-Whitepaper-Inexsmar-A4-en-EN.pdf","https://app.box.com/s/mlbeyha2vu6a5b8ystgdk6fdew4f6r98"],"report_names":["Bitdefender-Whitepaper-Inexsmar-A4-en-EN","Bitdefender_Whitepaper-Inexsmar-A4-en-EN(07-18-2017)"],"threat_actors":[{"id":"1dadf04e-d725-426f-9f6c-08c5be7da159","created_at":"2022-10-25T15:50:23.624538Z","updated_at":"2026-09-20T02:00:04.210777Z","deleted_at":null,"main_name":"Darkhotel","aliases":["Darkhotel","DUBNIUM","Zigzag Hail"],"source_name":"MITRE:Darkhotel","tools":null,"source_id":"MITRE","reports":null},{"id":"2b4eec94-7672-4bee-acb2-b857d0d26d12","created_at":"2023-01-06T13:46:38.272109Z","updated_at":"2026-09-20T02:00:03.323223Z","deleted_at":null,"main_name":"DarkHotel","aliases":["ATK52","Karba","Luder","Nemim","Shadow Crane","TUNGSTEN BRIDGE","T-APT-02","DUBNIUM","Nemin","SIG25","Zigzag Hail","Fallout Team","Tapaoux","APT-C-06","G0012"],"source_name":"MISPGALAXY:DarkHotel","tools":[],"source_id":"MISPGALAXY","reports":null},{"id":"c90dcdfb-7e9a-4a10-ae7a-58c69c973250","created_at":"2026-09-17T02:00:03.952525Z","updated_at":"2026-09-20T02:00:04.214414Z","deleted_at":null,"main_name":"TUNGSTEN BRIDGE","aliases":["APT-C-06 ","ATK52 ","CTG-1948 ","DUBNIUM ","DarkHotel ","Fallout Team ","Shadow Crane ","Zigzag Hail "],"source_name":"Secureworks:TUNGSTEN BRIDGE","tools":["Nemim","Tapaoux"],"source_id":"Secureworks","reports":null},{"id":"c0cedde3-5a9b-430f-9b77-e6568307205e","created_at":"2022-10-25T16:07:23.528994Z","updated_at":"2026-09-20T02:00:05.76319Z","deleted_at":null,"main_name":"DarkHotel","aliases":["APT-C-06","ATK 52","CTG-1948","Dubnium","Fallout Team","G0012","G0126","Higaisa","Luder","Operation DarkHotel","Operation Daybreak","Operation Inexsmar","Operation PowerFall","Operation The Gh0st Remains the Same","Purple Pygmy","SIG25","Shadow Crane","T-APT-02","TieOnJoe","Tungsten Bridge","Zigzag Hail"],"source_name":"ETDA:DarkHotel","tools":["Asruex","DarkHotel","DmaUp3.exe","GreezeBackdoor","Karba","Nemain","Nemim","Ramsay","Retro","Tapaoux","Trojan.Win32.Karba.e","Virus.Win32.Pioneer.dx","igfxext.exe","msieckc.exe"],"source_id":"ETDA","reports":null}],"ts_created_at":1789783322,"ts_updated_at":1789869719,"ts_creation_date":1500391788,"ts_modification_date":1500391803,"files":{"pdf":"https://archive.orkl.eu/39e53915de468512258066c3ae2875770bd68c45.pdf","text":"https://archive.orkl.eu/39e53915de468512258066c3ae2875770bd68c45.txt","img":"https://archive.orkl.eu/39e53915de468512258066c3ae2875770bd68c45.jpg"}},{"id":"58579e0f-4177-4b4b-929b-17146c9c987d","created_at":"2026-09-19T02:01:50.767293Z","updated_at":"2026-09-20T02:01:25.470716Z","deleted_at":null,"sha1_hash":"fdf53fac0af9cced76179fb1b9df0ce009952e36","title":"North Korea-linked APT attack found disguised as a digital asset wallet service customer center","llm_title":"","authors":"ESTSecurity","file_creation_date":"2022-02-21T00:52:14Z","file_modification_date":"2022-02-21T00:52:14Z","file_size":843363,"plain_text":"North Korea-linked APT attack found disguised as a\n\ndigital asset wallet service customer center!\n\nblog.alyac.co.kr/4501\n\nDetailed content\n\nbody title\n\nNorth Korea-linked APT attack found disguised as a digital asset wallet service customer\ncenter!\n\nMalware analysis report\nby pill 4 2022. 2. 16. 14:55\n\nmain text\n\nHello? This is the East Security Security Response Center (ESRC). \nA malicious file disguised as the Klip customer center was recently discovered, and users\nneed to be extra careful.\n\nFebruary 16, 2022\n\n1/5\n\nKlip is a digital asset wallet service developed by Ground X, a blockchain-related subsidiary\nof Kakao. The file found this time was distributed under the file name '[Klip Customer\nCenter] Mistransmission_Token Resolution_Guide.doc'.\n\n[Figure 1] Screen inducing users to click the content use button\n\nThe file contains malicious macros, convincing users to click the Enable Content button,\nclaiming that the document is protected.\n\nIf the user clicks the use content button, it is written like a file sent from the actual Klip\ncustomer center, causing the user to mistake it for a real normal file.\n\n2/5\n\n[Figure 2] Klip customer center camouflage file\n\nHowever, that file contains the macro code, and the macro runs in the background.\n\n3/5\n\n[Figure 3] Macros included in malicious files\n\nWhen the macro is executed, the file is dropped in xml format, and the dropped file is\nautomatically executed and then attempts to connect to the C\u0026C.\n\n[Figure 4] xml file dropped after macro execution\n\nHowever, at the time of analysis, access to the C\u0026C server was not possible, so further\nanalysis was not possible.\n\n4/5\n\nThis threat has been identified as an extension of the 'Smoke Screen' campaign, which is one\nof the three major threats of 'Thallium (also known as Kimsuky)'.\n\nIoC\n\nhxxp://asenal.medianewsonline[.]com/good/luck/flavor/list.php?query=1 \nhxxp://asenal.medianewsonline[.]com/good/luck/flavor/show.php\n\nCurrently, the pill is being detected as Trojan.Downloader.DOC.Gen .\n\nAttributionnon-profitchange prohibited\n\n5/5","extraction_quality":1,"language":"EN","sources":["APTnotes"],"origins":["web"],"references":["https://app.box.com/s/sn6863bx5gk1i1o2kw7t5m2fk5s1f6iq"],"report_names":["alyac_NKorea-digital-asset-wallet-customer-center(02-16-2022)"],"threat_actors":[{"id":"191d7f9a-8c3c-442a-9f13-debe259d4cc2","created_at":"2022-10-25T15:50:23.280374Z","updated_at":"2026-09-20T02:00:03.976727Z","deleted_at":null,"main_name":"Kimsuky","aliases":["Kimsuky","Black Banshee","Velvet Chollima","Emerald Sleet","THALLIUM","APT43","TA427","Springtail","Earth Kumiho","PatheticSlug"],"source_name":"MITRE:Kimsuky","tools":["Troll Stealer","HTTPTroy","schtasks","certutil","Amadey","GoBear","Brave Prince","CSPY Downloader","gh0st RAT","AppleSeed","Gomir","NOKKI","QuasarRAT","Gold Dragon","PsExec","KGH_SPY","Mimikatz","BabyShark","TRANSLATEXT"],"source_id":"MITRE","reports":null},{"id":"760f2827-1718-4eed-8234-4027c1346145","created_at":"2023-01-06T13:46:38.670947Z","updated_at":"2026-09-20T02:00:03.863152Z","deleted_at":null,"main_name":"Kimsuky","aliases":["THALLIUM","Springtail","Thallium","Operation Stolen Pencil","APT43","Sparkling Pisces","Velvet Chollima","Black Banshee","G0086","Emerald Sleet"],"source_name":"MISPGALAXY:Kimsuky","tools":["xrat","QUASARRAT","RDP Wrapper","TightVNC","BabyShark","RevClient"],"source_id":"MISPGALAXY","reports":null},{"id":"892dd3f3-26c7-4ca4-820a-0b0c7b81e41c","created_at":"2026-09-17T02:00:03.686979Z","updated_at":"2026-09-20T02:00:03.994744Z","deleted_at":null,"main_name":"NICKEL KIMBALL","aliases":["ARCHIPELAGO ","Black Banshee ","ITG16 ","Kimsuky ","TA406 ","UAT-5394 ","Velvet Chollima "],"source_name":"Secureworks:NICKEL KIMBALL","tools":["BabyShark","FastFire","FastSpy","FireViewer","KimJongRAT","Konni","ReconShark"],"source_id":"Secureworks","reports":null},{"id":"71a1e16c-3ba6-4193-be62-be53527817bc","created_at":"2022-10-25T16:07:23.753455Z","updated_at":"2026-09-20T02:00:05.965919Z","deleted_at":null,"main_name":"Kimsuky","aliases":["APT 43","Black Banshee","Emerald Sleet","G0086","G0094","ITG16","KTA082","Kimsuky","Larva-24005","Larva-25004","Operation Baby Coin","Operation Covert Stalker","Operation DEEP#DRIVE","Operation DEEP#GOSU","Operation Kabar Cobra","Operation Mystery Baby","Operation Red Salt","Operation Smoke Screen","Operation Stealth Power","Operation Stolen Pencil","SharpTongue","Sparkling Pisces","Springtail","TA406","TA427","Thallium","UAT-5394","Velvet Chollima"],"source_name":"ETDA:Kimsuky","tools":["AngryRebel","AppleSeed","BITTERSWEET","BabyShark","BoBoStealer","CSPY Downloader","Farfli","FlowerPower","Gh0st RAT","Ghost RAT","Gold Dragon","GoldDragon","GoldStamp","JamBog","KGH Spyware Suite","KGH_SPY","KPortScan","KimJongRAT","Kimsuky","LATEOP","LOLBAS","LOLBins","Living off the Land","Lovexxx","MailPassView","Mechanical","Mimikatz","MoonPeak","Moudour","MyDogs","Mydoor","Network Password Recovery","PCRat","ProcDump","PsExec","ReconShark","Remote Desktop PassView","SHARPEXT","SWEETDROP","SmallTiger","SniffPass","TODDLERSHARK","TRANSLATEXT","Troll Stealer","TrollAgent","VENOMBITE","WebBrowserPassView","xRAT"],"source_id":"ETDA","reports":null}],"ts_created_at":1789783310,"ts_updated_at":1789869685,"ts_creation_date":1645404734,"ts_modification_date":1645404734,"files":{"pdf":"https://archive.orkl.eu/fdf53fac0af9cced76179fb1b9df0ce009952e36.pdf","text":"https://archive.orkl.eu/fdf53fac0af9cced76179fb1b9df0ce009952e36.txt","img":"https://archive.orkl.eu/fdf53fac0af9cced76179fb1b9df0ce009952e36.jpg"}},{"id":"6cfa02fc-b4cc-4847-b7cf-b4a1dc819e12","created_at":"2026-09-19T02:01:34.025355Z","updated_at":"2026-09-20T02:01:25.966007Z","deleted_at":null,"sha1_hash":"bd5213ef27672de12acca481930ef2c94e07f424","title":"Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping","llm_title":"","authors":"","file_creation_date":"0001-01-01T00:00:00Z","file_modification_date":"0001-01-01T00:00:00Z","file_size":428418,"plain_text":"https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html\n\nChess.com Leak Exposes 7.3 Million Users – Evidence Points to\n\nScraping\n\nBy Pierluigi Paganini\n\nPublished: 2026-08-14 · Archived: 2026-09-19 02:00:38 UTC\n\n7.3 million Chess.com profiles leaked online: the data is genuine, but evidence\n\npoints to large-scale scraping, not a server breach.\n\nFree is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB\n\nfile containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no\n\nransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it\n\nisn’t, on the evidence, is a hack.\n\nPage 1 of 3\n\nhttps://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html\n\n“The archive is a single 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table: one header row and\n\n7,337,395 records, each with 38 fields. The schema is chess.com-specific throughout. Alongside the obvious\n\nidentifiers, email, partial email, username, user ID, UUID, first and last name, country, location and locale, it\n\ncarries platform state: chess title, points, skill level, premium status and label, verification and activation flags,\n\nbest rating and rating type, official rating, member-since and last-login timestamps.” reads the report published\n\nby Ransomnew. “Two fields at the end are the interesting ones. Every record\n\nhas  gam_audiences  and  audiences_member_of  populated, Google Ad Manager audience segments, with values\n\nlike coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting. Those are\n\nmarketing-stack fields, not profile data. They do not appear in chess.com’s public API.”\n\nThe file carries email addresses, usernames, real names, countries, chess ratings, subscription tiers, and something\n\nodder: internal Google Ad Manager audience tags, the kind of marketing segmentation data that never shows up in\n\nchess.com’s public API. Roughly three-quarters of records include an email address. There are no passwords, no\n\npassword hashes, and no payment data anywhere in the file, which matters a lot for how seriously affected users\n\nneed to react.\n\nProving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a\n\nversion-1 identifier, the kind that embeds the exact timestamp it was generated, and researchers decoded that\n\nhidden timestamp across 200,000 sample records to compare it against each account’s registration date. The match\n\nrate came back at 100%, which isn’t something anyone could fake without possessing actual chess.com-issued\n\nidentifiers down to the millisecond.\n\nThree separate details point toward scraping rather than an actual system breach. The data wasn’t captured in one\n\nmoment, it was stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job\n\nrather than a single database dump. About 7.4% of user records appear twice, the same accounts revisited on\n\ndifferent days, something that simply doesn’t happen inside a genuine database export.\n\nThis has happened to chess.com before, and the company was blunt about it at the time. Back in 2023, a similar\n\nleak of 828,000 records surfaced with a nearly identical field structure, and chess.com stated plainly,\n\nPage 2 of 3\n\nhttps://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html\n\n“In November 2023 a threat actor published 828,000 chess.com records with a near-identical field set.\n\nChess.com’s response then was unambiguous: as it told Hackread, “This was NOT a data breach.” continues the\n\nreport. “Our infrastructure, member accounts, and data such as passwords are secure.” The data had been pulled\n\nby abusing the platform’s find-friends feature, feeding in externally sourced email addresses to resolve them\n\nagainst accounts. A second scrape affecting roughly 476,000 users followed. This 2026 file is the same technique\n\nat roughly nine times the scale.”\n\nThat earlier incident came from abusing the platform’s find-friends feature to resolve external email lists against\n\nreal accounts; this new file looks like the same technique running at roughly nine times the scale.\n\nOne detail doesn’t fit a purely public-facing scrape, though. Advertising-audience segment data isn’t something\n\nchess.com’s open API exposes, and it appears on every single row in this file, which suggests whoever built this\n\nhad access to an authenticated or internal-facing endpoint rather than just the public developer tools. That’s the\n\nspecific question chess.com is best positioned to answer, and it’s the one that actually matters for understanding\n\nhow this happened.\n\nThe account distributing the file, going by V0idix, isn’t monetizing anything here. The same handle has posted\n\ndozens of free database dumps across other unrelated companies, building reputation through volume rather than\n\nthrough sales, which fits a collector who harvests and republishes data rather than someone selling access to a\n\nfresh intrusion.\n\nNone of this means chess.com users should shrug it off just because passwords weren’t exposed. A verified email\n\nsitting next to a real name, country, skill rating, and subscription tier is more than enough raw material for a\n\nconvincing phishing message about a membership renewal or a fair-play dispute. The right response isn’t\n\npanicking about a hacked account, it’s treating unexpected chess.com emails with more suspicion than usual and\n\nchecking whether that same email address has turned up anywhere else, since reused credentials remain the far\n\nmore dangerous exposure than anything sitting in this particular file.\n\nFollow me on Twitter: @securityaffairs and Facebook and Mastodon\n\nPierluigi Paganini\n\n(SecurityAffairs – hacking, Chess.com)\n\nSource: https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html\n\nPage 3 of 3","extraction_quality":1,"language":"EN","sources":["MISPGALAXY"],"origins":["web"],"references":["https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html"],"report_names":["chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html"],"threat_actors":[{"id":"172415b7-c5f8-42b0-bac5-11fb5f877aa6","created_at":"2026-09-19T02:00:05.612685Z","updated_at":"2026-09-20T02:00:06.006666Z","deleted_at":null,"main_name":"V0idix","aliases":[],"source_name":"MISPGALAXY:V0idix","tools":[],"source_id":"MISPGALAXY","reports":null}],"ts_created_at":1789783294,"ts_updated_at":1789869685,"ts_creation_date":0,"ts_modification_date":0,"files":{"pdf":"https://archive.orkl.eu/bd5213ef27672de12acca481930ef2c94e07f424.pdf","text":"https://archive.orkl.eu/bd5213ef27672de12acca481930ef2c94e07f424.txt","img":"https://archive.orkl.eu/bd5213ef27672de12acca481930ef2c94e07f424.jpg"}},{"id":"744b46a1-2bd7-4c48-92c1-ac8b33839b11","created_at":"2026-09-19T02:01:21.375007Z","updated_at":"2026-09-20T02:02:03.588363Z","deleted_at":null,"sha1_hash":"273ee4e079f844e09539d276a77789252720df92","title":"Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection","llm_title":"","authors":"","file_creation_date":"0001-01-01T00:00:00Z","file_modification_date":"0001-01-01T00:00:00Z","file_size":612868,"plain_text":"https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html\n\nRussian State-Sponsored Hackers Use Claude to Rebuild Malware\n\nAfter Detection\n\nBy The Hacker News\n\nPublished: 2026-09-11 · Archived: 2026-09-19 02:00:15 UTC\n\nAnthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that\n\nabused Claude for developing an AI-assisted workflow to get ahead of the detection curve.\n\nThe operation has been attributed to a cyber espionage group it calls GTG-20006 (where \"GTG\" stands for\n\nGenerative Threat Group), which aligns with broader reporting linking the cluster to Midnight Blizzard (aka\n\nAPT29 and Cozy Bear).\n\nThis actor is said to have developed an AI-driven process to automatically rebuild and re-deploy their toolkit if it\n\nwas detected by security products, thereby undermining defenders' ability to block the artifacts via static\n\ndetections.\n\nAttacks mounted by GTG-20006 have targeted military intelligence targets in Ukrainian and European\n\ngovernments, along with diplomatic and defense organizations and individuals connected to U.S. foreign policy.\n\nThe toolkit includes a number of programs -\n\nTwo Windows-based implants\n\nA mobile exploitation kit\n\nA credential stealing tool that targets browser password stores\n\nA phishing platform designed to mimic priority targets like government organizations, and\n\nPage 1 of 3\n\nhttps://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html\n\nAn administrative console used to manage compromised accounts\n\n\"The actor also used AI to monitor how well their tools evaded detections from known security defenses,\"\n\nAnthropic explained. \"If their monitoring AI agents identified that any of their deployed malware was detected by\n\na security product, agents would then set about the process of autonomously modifying and rebuilding the\n\nmalware to evade the existing detections.\"\n\nOnce the artifacts can bypass detection, they are staged on disposable hosting servers to which victims are\n\nredirected to so as to retrieve the malware via phishing, ClickFix, and DNS hijacking schemes.\n\nThe threat actor has also been observed using AI workflows to register domains, set up the hosting infrastructure\n\nused to send phishing emails, as well as to deliver the messages and monitor command-and-control (C2) channels\n\nfor successful compromises.\n\nMore than 20 distinct organizations were singled out over the course of the reconnaissance and live operations.\n\nThis included government ministries, defense and intelligence bodies, embassies and diplomatic missions, think\n\ntanks, and defense-industrial companies, mainly in Ukraine and Europe. The attacks also extended to the Middle\n\nEast and maritime-related government agencies in Asia.\n\nThese efforts also overlapped with a campaign dubbed CaptiveCrunch that was documented in July and August\n\n2026 by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.\n\n\"The actor compromised at least three hospitality vendors that operate hotel guest Wi-Fi,\" Anthropic said. \"They\n\nused compromised admin credentials to modify DNS records so that they pointed to services owned by the actor\n\n(a technique known as DNS hijacking). Guests of hotels using the compromised vendors who connected to the\n\nhotel Wi-Fi had their traffic, device identifier, and IP address sent to the actor's servers.\"\n\nIn the next stage, victims were served ClickFix-style lures to deliver Windows, Android, and iOS malware tailored\n\nto their device -\n\nWindows - PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc\n\nAndroid - GiftDrop, a rebranded version of GiftsExpress Android surveillance RAT\n\niOS - DarkSword\n\nFurthermore, the threat actor has been found to use data stolen from the hotel management systems and the\n\nindividual guests' devices to identify additional targets, particularly individuals associated with Ukraine, such as\n\ngovernment officials and drone manufacturers.\n\nThis is complemented by attempts to take over victims' WhatsApp accounts using headless browsers to link victim\n\naccounts as companion devices and ultimately bulk-exporting Russian and Ukrainian language conversations from\n\nthem while suppressing read receipts.\n\nPage 2 of 3\n\nhttps://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html\n\n\"The actor also targeted surveillance platforms,\" Anthropic said. \"They found authorization flaws in the\n\napplication interface of camera streaming services, and from there they enumerated users and harvested tokens\n\nthat granted them access to the victims’ live camera streams.\"\n\nGTG-20006 has been attributed to an intrusion targeting a North African government technology authority,\n\nleveraging credentials to a VPN appliance to hijack the central account server and exfiltrate the entire credential\n\ndatabase consisting of over 300,000 national identity records and the commercial registry data of more than half a\n\nmillion companies operating in the country.\n\nAlso developed by the threat actor is a cloud email espionage platform, which used a device code phishing\n\nframework codenamed Embassy Kit to orchestrate a Microsoft 365 token theft campaign targeting diplomatic and\n\ngovernment personnel, resulting in the unauthorized access and exfiltration of mail records from at least eight\n\norganizations, including a national prosecutor's office, a military education institute, and a regional\n\nintergovernmental organization.\n\nThe threat actor has also been observed delivering Windows credential stealers via fake update-themed social\n\nengineering lures, along with auxiliary tools for facilitating remote access and tampering with the victim\n\nmachine's security updates so that the artifacts remain undetected.\n\n\"The actor used AI at every point in their operations,\" Anthropic said. \"In on-premises environments, the actor\n\nused AI to monitor the stealth and persistence of their implants. \"The result of the above is that AI has inverted the\n\ncost back onto defenders. Previously, defenders might have been able to slow an attacker's operational tempo via\n\nthe deployment of a new detection.\"\n\nFound this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content\n\nwe post.\n\nSource: https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html\n\nPage 3 of 3","extraction_quality":1,"language":"EN","sources":["MISPGALAXY"],"origins":["web"],"references":["https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html"],"report_names":["russian-state-sponsored-hackers-use.html"],"threat_actors":[{"id":"bdcbb277-59d1-48fc-9ace-78bba9820370","created_at":"2026-09-17T02:00:03.776668Z","updated_at":"2026-09-20T02:00:04.077756Z","deleted_at":null,"main_name":"IRON RITUAL","aliases":["APT29","Blue Dev 5 ","BlueBravo ","Cloaked Ursa ","Dark Halo ","Midnight Blizzard ","StellarParticle ","UNC2452 "],"source_name":"Secureworks:IRON RITUAL","tools":["Cobalt Strike","GoldFinder","GoldMax","RAINDROP","SUNBURST","Sibot","TEARDROP"],"source_id":"Secureworks","reports":null},{"id":"9b625e2d-a092-420f-a17f-a8a7d1bbe934","created_at":"2026-09-17T02:00:03.779046Z","updated_at":"2026-09-20T02:00:04.079856Z","deleted_at":null,"main_name":"IRON HEMLOCK","aliases":["APT29 ","ATK7 ","Blue Kitsune ","Cozy Bear ","The Dukes","UNC2452 ","YTTRIUM "],"source_name":"Secureworks:IRON HEMLOCK","tools":["CosmicDuke","CozyCar","CozyDuke","HAMMERTOSS","LiteDuke","MiniDuke","OnionDuke","PolyglotDuke","RegDuke Loader","SeaDuke"],"source_id":"Secureworks","reports":null},{"id":"46b3c0fc-fa0c-4d63-a38a-b33a524561fb","created_at":"2023-01-06T13:46:38.393409Z","updated_at":"2026-09-20T02:00:03.487711Z","deleted_at":null,"main_name":"APT29","aliases":["COZY BEAR","IRON HEMLOCK","Grizzly Steppe","TA421","UAC-0029","Group 100","The Dukes","SeaDuke","ATK7","Blue Kitsune","ITG11","Nobelium","Minidionis","YTTRIUM","G0016","BlueBravo","ICE RELIC","Cloaked Ursa","ICECAP"],"source_name":"MISPGALAXY:APT29","tools":["SNOWYAMBER","HALFRIG","QUARTERRIG"],"source_id":"MISPGALAXY","reports":null},{"id":"70872c3a-e788-4b55-a7d6-b2df52001ad0","created_at":"2023-01-06T13:46:39.18401Z","updated_at":"2026-09-20T02:00:04.264282Z","deleted_at":null,"main_name":"UNC2452","aliases":["DarkHalo","StellarParticle","NOBELIUM","Solar Phoenix","Midnight Blizzard"],"source_name":"MISPGALAXY:UNC2452","tools":["SNOWYAMBER","HALFRIG","QUARTERRIG"],"source_id":"MISPGALAXY","reports":null},{"id":"20d3a08a-3b97-4b2f-90b8-92a89089a57a","created_at":"2022-10-25T15:50:23.548494Z","updated_at":"2026-09-20T02:00:04.175472Z","deleted_at":null,"main_name":"APT29","aliases":["APT29","IRON RITUAL","IRON HEMLOCK","NobleBaron","Dark Halo","NOBELIUM","UNC2452","YTTRIUM","The Dukes","Cozy Bear","CozyDuke","SolarStorm","Blue Kitsune","UNC3524","Midnight Blizzard"],"source_name":"MITRE:APT29","tools":["PinchDuke","ROADTools","WellMail","CozyCar","Mimikatz","Tasklist","OnionDuke","FatDuke","POSHSPY","EnvyScout","SoreFang","GeminiDuke","reGeorg","GoldMax","FoggyWeb","SDelete","PolyglotDuke","AADInternals","MiniDuke","SeaDuke","Sibot","RegDuke","CloudDuke","GoldFinder","AdFind","PsExec","NativeZone","Systeminfo","ipconfig","Impacket","Cobalt Strike","PowerDuke","QUIETEXIT","HAMMERTOSS","BoomBox","CosmicDuke","WellMess","VaporRage","LiteDuke"],"source_id":"MITRE","reports":null},{"id":"a0ee9d9a-bd20-4574-a5ac-b1ed8c157ee0","created_at":"2026-09-19T02:00:05.610322Z","updated_at":"2026-09-20T02:00:06.004351Z","deleted_at":null,"main_name":"GTG-20006","aliases":[],"source_name":"MISPGALAXY:GTG-20006","tools":[],"source_id":"MISPGALAXY","reports":null},{"id":"f27790ff-4ee0-40a5-9c84-2b523a9d3270","created_at":"2022-10-25T16:07:23.341684Z","updated_at":"2026-09-20T02:00:05.597288Z","deleted_at":null,"main_name":"APT 29","aliases":["APT 29","ATK 7","Blue Dev 5","BlueBravo","Cloaked Ursa","CloudLook","Cozy Bear","Dark Halo","Earth Koshchei","G0016","Grizzly Steppe","Group 100","ITG11","Iron Hemlock","Iron Ritual","Midnight Blizzard","Minidionis","Nobelium","NobleBaron","Operation Ghost","Operation Office monkeys","Operation StellarParticle","SilverFish","Solar Phoenix","SolarStorm","StellarParticle","TEMP.Monkeys","The Dukes","UNC2452","UNC3524","Yttrium"],"source_name":"ETDA:APT 29","tools":["7-Zip","ATI-Agent","AdFind","Agentemis","AtNow","BEATDROP","BotgenStudios","CEELOADER","Cloud Duke","CloudDuke","CloudLook","Cobalt Strike","CobaltStrike","CosmicDuke","Cozer","CozyBear","CozyCar","CozyDuke","Danfuan","EnvyScout","EuroAPT","FatDuke","FoggyWeb","GeminiDuke","Geppei","GoldFinder","GoldMax","GraphDrop","GraphicalNeutrino","GraphicalProton","HAMMERTOSS","HammerDuke","LOLBAS","LOLBins","LiteDuke","Living off the Land","MagicWeb","Mimikatz","MiniDionis","MiniDuke","NemesisGemina","NetDuke","OnionDuke","POSHSPY","PinchDuke","PolyglotDuke","PowerDuke","QUIETEXIT","ROOTSAW","RegDuke","Rubeus","SNOWYAMBER","SPICYBEAT","SUNSHUTTLE","SeaDaddy","SeaDask","SeaDesk","SeaDuke","Sharp-SMBExec","SharpView","Sibot","Solorigate","SoreFang","TinyBaron","WINELOADER","WellMail","WellMess","cobeacon","elf.wellmess","reGeorg","tDiscoverer"],"source_id":"ETDA","reports":null}],"ts_created_at":1789783281,"ts_updated_at":1789869723,"ts_creation_date":0,"ts_modification_date":0,"files":{"pdf":"https://archive.orkl.eu/273ee4e079f844e09539d276a77789252720df92.pdf","text":"https://archive.orkl.eu/273ee4e079f844e09539d276a77789252720df92.txt","img":"https://archive.orkl.eu/273ee4e079f844e09539d276a77789252720df92.jpg"}},{"id":"f2ac65d6-7e37-4652-8057-26970166bbd3","created_at":"2026-09-17T02:03:27.768Z","updated_at":"2026-09-20T02:02:31.264664Z","deleted_at":null,"sha1_hash":"f9128ffb075b0991d429db61c8d28bf459fddf4b","title":"StealC-Malware-Analysis/Reports/StealC-V2-EN.md at main · Yavuzhanzgen/StealC-Malware-Analysis","llm_title":"","authors":"","file_creation_date":"0001-01-01T00:00:00Z","file_modification_date":"0001-01-01T00:00:00Z","file_size":9181190,"plain_text":"https://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nStealC-Malware-Analysis/Reports/StealC-V2-EN.md at main ·\n\nYavuzhanzgen/StealC-Malware-Analysis\n\nBy Yavuzhanzgen\n\nArchived: 2026-09-17 02:01:13 UTC\n\nLegal Disclaimer\n\nThis repository is intended solely for malware analysis, reverse engineering research, and educational purposes.\n\nAll malware samples were analyzed in an isolated laboratory environment.\n\nStealC V2 Malware Technical Analysis\n\nStatic Analysis • Dynamic Analysis • Reverse Engineering • YARA • MITRE ATT\u0026CK\n\nPage 1 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nM A LWA R E S T E A L C TYPE I N F O R M A T I O N S T E A L E R\n\nL A N G U A G E C + +\n\nA N A LY S I S S T A T I C + D Y N A M I C\n\nI O C E X T R A C T E D\n\nREPORT C O M P L E T E D L I C E N S E\n\nInfection Chain\n\nQuickFetch.exe\n\n│\n\n▼\n\nCAB Resource Extraction\n\n│\n\n▼\n\nWagner.a3x (AutoIt)\n\n│\n\n▼\n\nPayload Deobfuscation\n\n│\n\n▼\n\nErlik.exe (StealC V2)\n\n│\n\n▼\n\nSystem Discovery\n\n│\n\n▼\n\nYA R A C U S T O M R U L E S\n\nM I T\n\nCredential and Wallet Theft\n\n│\n\n▼\n\nRC4 + Base64 Encryption\n\n│\n\n▼\n\nHTTP POST (JSON)\n\n│\n\n▼\n\nStealC C2 Server\n\n# QuickFetch.exe Analysis\n\nName QuickFetch\n\nMD5 cb3694044c8b3850ec1414a2bb56e5a9\n\nSHA256 1d9b44ff02821dbe186f121b8674e5e621d0e7ba9f876e3cf1e918f15817f13c\n\nFile Type PE64/EXE\n\nStatic Analysis\n\nFigure 2. QuickFetch File Information\n\nThe analyzed executable is a 64-bit Portable Executable (PE)\n\nThe file size is approximately 1.88 MB. Embedded metadata shows\n\nfile compiled for the Microsoft Windows operating system.\n\nPage 2 of 24\n\nP L AT F O R M W I N D O W S\n\nM I T R E A T T \u0026 C K\n\nMicrosoft Corporation as the manufacturer and\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nWin32 Cabinet Self Extractor as the product information. This indicates that the executable was created using Microsoft's\n\nCabinet extraction infrastructure.\n\nFigure 3. PE64 File Structure\n\nThe malware was compiled in C++ using Microsoft Visual Studio 2022. The sample exhibits a high entropy value due to\n\nits compression using Microsoft Cabinet technology.\n\nDynamic Analysis\n\nFigure 4. Creation of the IXP000.TMP Directory\n\nThe malware creates a temporary directory named IXP000.TMP within the Windows TEMP directory. This operation is\n\nperformed using the CreateDirectoryA Windows API function.\n\nFigure 5. Extraction of the Wagner.a3x File\n\nQuickFetch contains an embedded CABINET resource. During execution, the malware extracts this resource using the\n\nfollowing Windows API functions:\n\nFindResourceA\n\nLoadResource\n\nLockResource\n\nThe extracted files are then written to the IXP000.TMP\n\noperation, the Wagner.a3x file is created.\n\ndirectory using the CreateFileA API function. As a result of this\n\nPage 3 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 6. Timestamp Manipulation\n\nThe malware modifies file timestamps after the files are extracted. It sequentially calls the following API functions to assign\n\nbackdated timestamps to the dropped files:\n\nDosDateTimeToFileTime\n\nLocalFileTimeToFileTime\n\nSetFileTime\n\nThis technique is intended to hide the actual creation times of the files, making forensic analysis more difficult.\n\nFigure 7. Modified File Timestamps\n\nAlthough the dropped files were actually created on\n\nmodify their timestamps to July 11, 2026.\n\nFigure 8. Execution of the AutoIt Code\n\nThe executable also contains a resource named POSTRUNPROGRAM\n\nthe ReadFile API, the malware executes the embedded command using the\n\nadvances the infection chain to the next stage.\n\n# Wagner.a3x Analysis\n\nName\n\nMD5\n\nSHA256\n\nWagner\n\n66f3c8236809b6a3f407aab81a33a934\n\nb72cd4f21fd948c47497e27098336c1f355da1335caa63b484af15444772a84a\n\nJuly 22, 2026, the malware uses the SetFileTime API function to\n\n. After reading the contents of this resource using\n\nCreateProcessA API function. This operation\n\nPage 4 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFile Type AutoIt Script (A3X)\n\nStatic Analysis\n\nFigure 9. Wagner File Information\n\nThe extracted Wagner.a3x file is a 2.37 MB script compiled with AutoIt v3. The sample does not contain a standard PE\n\n(Portable Executable) header; instead, it uses a custom container format specific to AutoIt.\n\nFigure 10. Obfuscated AutoIt Script\n\nAnalysis of the file revealed the AU3!EA06 magic header. This header confirms that the sample is a compiled AutoIt script.\n\nFigure 11. AutoIt Code Extraction\n\nPage 5 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nThe AutoIt Extractor tool was used to extract the embedded AutoIt script and facilitate further analysis. Using this tool, the\n\nscript was extracted and partially deobfuscated.\n\nFigure 12. Decompiled AutoIt Script\n\nAlthough the script was successfully extracted, the resulting AutoIt source code still contains extensive obfuscation.\n\nAdditional cleanup and manual reverse engineering are required to understand the payload's actual execution logic.\n\nDynamic Analysis\n\nFigure 13. Payload Reconstruction\n\nFollowing the cleanup and deobfuscation of the script, the final malicious payload is reconstructed from numerous\n\nencrypted hexadecimal data blocks stored within the $dfjzfnagjlwyw variable.\n\nThese fragments are first concatenated using the Binary() function and then decrypted through multiple nested calls to the\n\nTYLERMAURITIUS function. Once the process is complete, a valid Portable Executable (PE) file beginning with the\n\nMZ (4D 5A) signature is obtained.\n\nFigure 14. Payload Validation\n\nTo enable more detailed analysis, the reconstructed payload was written to disk as Erlik.exe using the FileWrite() function.\n\nThis executable represents the main payload of the StealC V2 malware, which will be examined in detail in the following\n\nPage 6 of 24\n\nsections.\n\nErlik.exe Analysis\n\nName\n\nMD5\n\nSHA256\n\nFile Type\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nErlik\n\n991fab1c038d3569e36e92251700935c\n\n0a47791a9c8ce6777d5d658d116168470f09e6b9564d9bdff44c352c9f524849\n\nPE64/EXE\n\nStatic Analysis\n\nFigure 15. Erlik File Information\n\nThe extracted StealC payload is a 64-bit Portable Executable (PE)\n\napproximately 766 KB.\n\nFigure 16. Encrypted Configuration Strings\n\nStatic analysis revealed that numerous configuration strings are stored\n\nalgorithm.\n\nThese encrypted data include:\n\nWindows API names\n\nDLL modules\n\nNetwork paths\n\nRegistry keys\n\nBrowser artifacts\n\nCommand and Control (C2) configuration values\n\nDynamic Analysis\n\nPage 7 of 24\n\nfile compiled for Microsoft Windows. The file size is\n\nBase64-encoded and encrypted using the RC4\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 17. RC4 String Decryption Process\n\nDuring execution, the malware first decodes the embedded configuration data using standard\n\nresulting data is then decrypted using the RC4 algorithm with the following hardcoded key:\n\nYKMmx1ZXae1qy6DtSm\n\nThe decryption process reveals numerous Windows API names and internal configuration values used throughout execution.\n\nValue Value\n\n5732ca5caae14cdab501 05\n\nkernel32.dll advapi32.dll\n\nGetProcAddress ExitProcess\n\nOpenEventW CreateEventW\n\nGetComputerNameW GetUserNameW\n\nTable 1. Strings Decrypted Using RC4\n\nFigure 18. Dynamic API Resolution\n\nInstead of statically importing Windows API functions, StealC dynamically resolves them at\n\nare decrypted using RC4, the malware loads the required DLL modules into memory using the\n\nthen obtains the addresses of the required functions through the GetProcAddress\n\nPage 8 of 24\n\nBase64 decoding. The\n\nValue\n\n08\n\nLoadLibraryA\n\nCloseHandle\n\nSleep\n\nGetUserDefaultLangID\n\nruntime. After the API names\n\nLoadLibraryA function and\n\nAPI.\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 19. Retrieving the Computer Name\n\nThe malware calls the GetComputerNameW Windows API function to obtain the computer name of the victim system.\n\nFigure 20. Retrieving the Username\n\nThe malware obtains the name of the logged-in Windows user through the\n\nFigure 21. Locale Check\n\nThe malware queries the operating system's default user language using the\n\nimplements a locale-based execution restriction mechanism. If the retrieved language ID matches one of the predefined\n\nlanguage IDs associated with Commonwealth of Independent States (CIS)\n\nexecution.\n\nLanguage ID\n\n0x0419\n\n0x0422\n\n0x0423\n\n0x043F\n\n0x0444\n\nTable 2. Language Blacklist\n\nFigure 22. Date Validation\n\nGetUserNameW API function.\n\nGetUserDefaultLangID API function and\n\ncountries, the malware terminates its\n\nRegion\n\nRussian\n\nUkrainian\n\nBelarusian\n\nKazakh\n\nUzbek\n\nPage 9 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nThe malware compares the current system date with\n\nterminated.\n\nThis behavior represents a built-in\n\ndate.\n\nFigure 23. Resolved APIs and Configuration Data\n\nFollowing the RC4 decryption process, the malware resolves:\n\nWindows API functions,\n\nBrowser artifacts,\n\nCommand and Control (C2) paths,\n\nOperating system resources,\n\nand prepares the configuration data required for credential theft and data exfiltration.\n\n## Table 3. Resolved APIs, Libraries, and Strings\n\nValue\n\n160.20.109.75\n\ngdi32.dll\n\ncrypt32.dll\n\nShell32.dll\n\nGdipCreateBitmapFromHBITMAP\n\nGdipDisposeImage\n\nRegCloseKey\n\nSelectObject\n\nRmGetList\n\nEnumDisplayDevicesW\n\nCopyFileA\n\nCreateDirectoryA\n\nCreateToolhelp32Snapshot\n\nWallets\n\nPOST\n\nv20.txt\n\nHistory\n\nCURRENT\n\nlogins.json\n\nDisplayName\n\nNetwork Info:\n\n05/08/2026. If the system date is later than this value, execution is\n\ncampaign expiration mechanism that automatically disables the malware after a specific\n\nValue\n\n/d19ca32cb5a444ac8b87.php\n\nrstrtmgr.dll\n\nrstrtgmr.dll\n\nNtdll.dll\n\nGdiplusStartup\n\nRegQueryValueExA\n\nCryptUnprotectData\n\nDeleteDC\n\nRmRegisterResources\n\nwsprintfA\n\nCreateNamedPipeA\n\nGetCurrentProcessId\n\nGetTimeZoneInformation\n\nFiles\n\nupload_file\n\nCookies\n\nBrowsers\n\nnss3.dll\n\npasswords.txt\n\nself_delete\n\nsystem_info.txt\n\nPage 10 of 24\n\nValue\n\ngdiplus.dll\n\nole32.dll\n\nUser32.dll\n\nGdipGetImageEncodersSize\n\nGdiplusShutdown\n\nRegEnumKeyExA\n\nCryptStringToBinaryA\n\nDeleteObject\n\nReleaseDC\n\nShellExecuteExA\n\nLocalAlloc\n\nGetSystemPowerStatus\n\nCreateProcessA\n\nProgramData\n\nencrypted_key\n\nLogin Data\n\nPlugins\n\nNSS_Init\n\ncookies.sqlite\n\nsteal_steam\n\nscreenshot.jpg\n\nValue\n\ncrypt32.dll\n\nwinhttp.dll\n\nShlwapi.dll\n\nGdipGetImageEncoders\n\nGdipSaveImageToStream\n\nRegQueryValueExW\n\nCreateCompatibleDC\n\nBitBlt\n\nGetKeyboardLayoutList\n\nFindNextFileA\n\nRemoveDirectoryA\n\nGetLocaleInfoW\n\nGetSystemTime\n\nContent-Type:\n\napplication/json\\\\r\\\\n\n\nv10.txt\n\nWeb Data\n\nIndexedDB\n\nNSS_Shutdown\n\nformhistory.sqlite\n\nsteal_outlook\n\nSoftware\\\\Valve\\\\Steam\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nValue\n\nSteamPath\n\nBuild\n\nTable 3. Resolved APIs, Libraries, and Strings\n\nValue Value Value\n\nSteam Monitor - RAM:\n\nhwid\n\nFigure 23. Preparation of the Initial JSON Record Data\n\nThe malware calls the GetWindowsDirectoryA API function to retrieve the Windows installation directory and\n\nincorporates this information into the system identification process. Together with the previously collected computer name,\n\nusername, and other system identifiers, this information is used to generate a unique Hardware ID (HWID).\n\nOnce the identification process is complete, the malware begins constructing a JSON-like data structure in memory that will\n\nbe sent to the Command and Control (C2) server.\n\nFigure 24. Sending an HTTP POST Request Using WinINet APIs\n\nThe malware first initializes a WinINet session by calling the InternetOpenW API function and configures the connection\n\nparameters through the InternetSetOptionA function. It then attempts to connect to the C2 server at 160[.]20[.]109[.]75\n\nusing the InternetConnectW API.\n\n/d19ca32cb5a444ac8b87.php\n\nIf the connection cannot be established, execution is transferred to an error-handling routine. If the connection is successful,\n\nthe malware creates an HTTP request using the HttpOpenRequestW API function with the POST method. The Content-\n\nType: application/json header is prepared, and the generated record data is sent to the C2 server through the\n\nHttpSendRequestW API.\n\nPage 11 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 25. Initial GET Request Sent to the C2 Server\n\nNetwork analysis shows that the malware sends a GET request to the following endpoint on the C2 server:\n\nd19ca32cb5a444ac8b87.php\n\nThe server responds to this request with a single line of encrypted data. This response is processed during the next stage of\n\nexecution.\n\nFigure 26. Decryption of the Server Response\n\nThe response received from the C2 server contains the \"blocked\" operation code. This value indicates that the IP address\n\nfrom which the request was sent is not authorized to communicate with the corresponding C2 infrastructure. Since the\n\noriginal C2 server was no longer active during the analysis, the hardcoded IP address within the malware was redirected to a\n\nsimulated C2 server prepared in the local environment.\n\nFigure 27. Wireshark Analysis of the POST Request\n\nPage 12 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nPacket capture records show that immediately after sending the POST request, the malware transmits an encrypted payload\n\nbeginning with igd7O.... In response, the server sends a second encrypted data block beginning with ii85LY.... This response\n\ncontains configuration data that will be used during the next stage of the malware's execution.\n\nFigure 28. Decrypted JSON Record Data\n\nAfter the transmitted data is decrypted using the following RC4 key:\n\n161c87d5a7ee4a63\n\nthe first message sent to the C2 server is identified as a JSON registration object containing information used to identify the\n\ncompromised system. This request registers the victim system with the botnet infrastructure.\n\nField\n\nBuild\n\nHWID\n\nType\n\nTable 4. Initial Registration JSON Fields\n\nDescription\n\nBotnet identifier (\"ja1\")\n\nUnique Hardware ID\n\nRegistration request (\"create\")\n\nFigure 29. Configuration Data Sent by the C2 Server\n\nAfter receiving the initial create request, the C2 server sends a configuration object containing settings that will be used by\n\nthe malware during runtime.\n\nThe configuration file contains an access token, operation status, randomly generated identifier values, and various\n\nbehavioral flags controlling screenshot capture, self-deletion, browser credential theft, and other post-exploitation functions,\n\nas well as data related to the targeted applications.\n\nPage 13 of 24\n\nhttps://gith\n\nBrowser\n\n360 Browser\n\nCent Browser\n\nChromium\n\nGoogle Chrome Canary\n\nOpera GX\n\nQQ Browser\n\nTorch Browser\n\nTable 5. Targeted Browsers\n\nWallet\n\nAllet\n\nBinance Wallet\n\nBrave Wallet\n\nCoin98 Wallet\n\nConan Wallet\n\nCyano Wallet\n\nElseware Wallet\n\nEVER Wallet\n\nGlass Wallet – Sui Wallet\n\nGuarda\n\nICONex\n\nKardiaChain Wallet\n\nLaso Finance\n\nLuckyCoin Wallet\n\nMartian Aptos Wallet\n\nMoon – Shop Online with\n\nBitcoin\n\nMyTonWallet\n\nOKX Wallet\n\nOrbiter Wallet\n\nPallad\n\nPirichain Wallet\n\nPulse Wallet Chromium\n\nRise – Aptos Wallet\n\nSaros Wallet\n\nSteemKeychain\n\nTerra Station Wallet\n\nTrust Wallet\n\nub.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nBrowser\n\n7Star\n\nChedot Browser\n\nCryptoTab Browser\n\nMaxthon Browser\n\nOpera Stable\n\nQuark Browser\n\nUC Browser\n\nWallet\n\nAstrone Wallet\n\nBitget Wallet\n\nC64 Wallet\n\nCoinbase Wallet Extension\n\nCraftCoin Wallet\n\nDAppPlay\n\nEnkrypt\n\nFinnie\n\nGoBo Wallet\n\nGuildWallet\n\nINTMAX Wallet\n\nKeplr\n\nLeap Terra Wallet\n\nLuckyStar – LuckyCoin\n\nWallet\n\nMavryk Wallet\n\nMorphis Wallet\n\nNami\n\nOneKey\n\nOVG Wallet\n\nPelagus\n\nPluto Wallet\n\nRabby\n\nRonin Wallet\n\nSender Wallet\n\nSubWallet – Polkadot W\n\nTezBox\n\nTronLink\n\nPage 14 of 24\n\nBrowser\n\nAmigo\n\nCocCoc Browser\n\nEpic Privacy Browser\n\nMicrosoft Edge\n\nPale Moon\n\nSigma AI Browser\n\nVivaldi\n\nWallet\n\nAuro Wallet (Mina\n\nProtocol)\n\nBOLT X\n\nCardano Priority Wallet\n\nCompass Wallet for Sei\n\nCreta Wallet\n\nEcto Wallet\n\nEQ Hub Wallet\n\nFluvi Wallet\n\nGoby\n\nHashPack\n\niWallet\n\nKeeper Wallet\n\nLiquality Wallet\n\nMagic Eden Wallet\n\nMetaMask\n\nMultiversX DeFi Wallet\n\nNeoLine\n\nOpenMask Wallet\n\nOxygen\n\nPetra Aptos Wallet\n\nPolymesh Wallet\n\nRainbow Wallet\n\nSafePal\n\nSolflare Wallet\n\nallet TapCoin\n\nTON Wallet\n\nUniltc Wallet\n\nBrowser\n\nBrave Browser\n\nComodo Dragon\n\nGoogle Chrome\n\nMozilla Firefox\n\nPerplexity Comet\n\nSogou Browser\n\nWallet\n\nBackpack Wallet\n\nBraavos Wallet\n\nCLV Wallet\n\nConla Wallet\n\nCVM Wallet\n\nElli – Sui Wallet\n\nEternl\n\nFrontier Wallet\n\nGrind Wallet\n\nHAVAH Wallet\n\nJaxx Liberty\n\nKHC\n\nLite Wallet\n\nMaiar DeFi Wallet\n\nMEW CX\n\nMWC Wallet\n\nNightly Wallet\n\nOpera Wallet\n\nPali Wallet\n\nPhantom\n\nPontem Aptos\n\nWallet\n\nReliable Wallet\n\nSafePal Wallet\n\nSollet\n\nTemple\n\nTonkeeper Wallet\n\nUniswap Extension\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nWallet\n\nVelas\n\nXFS Wallet\n\nTable 6. Targeted Cryptocurrency Wallets\n\nPassword Manager\n\nBitwarden\n\nDashlane\n\nLastPass\n\nRoboForm\n\nTable 7. Targeted Password Managers\n\nApplication\n\nCrypto-Cardholder by PST\n\nMoon – Shop Online with Bitcoin\n\nStock Up: DeFi, NFT and W\n\nTable 8. Targeted Web3 and Blockchain Applications\n\nApplication\n\nAuthenticator\n\nEOS Authenticator\n\nTable 9. Targeted Authentication Applications\n\nApplication\n\nDiscord\n\nTelegram Desktop\n\nTable 10. Targeted Messaging Applications\n\nCloud Provider\n\nAWS (.aws)\n\nTable 11. Targeted Cloud Credentials\n\nPlatform\n\nBattle.net\n\nTable 12. Targeted Gaming Platforms\n\nApplication\n\nOpenVPN Connect\n\nTable 13. Targeted VPN and FTP Applications\n\nApplication\n\nMicrosoft Sticky Notes\n\nWallet\n\nVelgazm\n\nXverse Wallet\n\nPassword Manager\n\nBrowserPass\n\nKeeper\n\nMYKI\n\nSplikity\n\n.NET\n\neb3 Extension\n\nCloud Provider\n\nAzure (.azure)\n\nPlatform\n\nUbisoft Connect (Uplay)\n\nApplication\n\nProtonVPN\n\nPage 15 of 24\n\nWallet\n\nVenom W\n\nYoroi\n\nApplication\n\nAuthy\n\nGAuth Authenticator\n\nApplication\n\nPidgin\n\nTox\n\nCloud Provider\n\nMicrosoft Identity Service (.IdentityService)\n\nApplication\n\nSimple Sticky Notes\n\nWallet\n\nallet XDEFI Wallet\n\nPassword Manager\n\nCommonKey\n\nKeePassXC\n\nNordPass\n\nZoho Vault\n\nApplication\n\nLaso Finance\n\nPortal DEX\n\nApplication\n\nFileZilla\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nTable 14. Targeted Note-Taking Applications\n\nFile Pattern File Pattern File Pattern\n\n*.txt *seed*.txt *private*.key\n\n*recovery*.txt *metamask*.json *pass*.txt\n\n*btc*.txt *eth*.txt *2fa*.txt\n\nTable 15. Targeted User Files\n\nFigure 30. Blacklist of Analysis and Virtualization Tools\n\nDuring execution, the malware maintains an internal blacklist containing the process names of commonly used analysis\n\ntools, reverse engineering applications, and virtualization software. At this stage, no comparison or detection operation is\n\nperformed.\n\nProcess Process Process Process\n\nWireshark ProcessHacker Fiddler ProcExp\n\nSysmon IDA\n\nCheat Engine Scylla\n\nx32dbg x64dbg\n\nScylla_x64 Scylla_x86\n\nWinDbg Resource Hacker Resource Hacker 32 Resource Hacker 64\n\nLordPE TCPView Netmon Sniffer\n\nAPI Monitor Radare2 ProcDump DbgView\n\nDetect It Easy DetectIt_Easy Dumpcap Netcat\n\nDependency Walker Dependencies ProDiscover Sysinternals\n\nSandboxie VMware VirtualBox VMTools\n\nVMwareService VMwareTray VBoxService VBoxTray\n\nprl_cc\n\nTable 16. Blacklisted Analysis and Virtualization Processes\n\nFigure 31. Retrieving the Current Username\n\nThe malware calls the GetUserNameW API to obtain the username of the currently logged-in user. The retrieved\n\ninformation is subsequently included in the victim profile sent to the Command and Control (C2) server.\n\nPage 16 of 24\n\nFile Pattern\n\n*mnemonic*.txt\n\n*login*.txt\n\nProcess\n\nProcmon\n\nOllyDbg\n\nImmunityDebugger\n\nGhidra\n\nSnort\n\nde4dot\n\nBinText\n\nNetLimiter\n\nVMwareService\n\nQEMU Guest Agent\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 32. Retrieving the Computer Name\n\nThe malware obtains the hostname of the infected system through the GetComputerNameW API.\n\nFigure 33. Retrieving the System Date\n\nThe malware uses the GetLocalTime API to retrieve the current system date from the operating system.\n\nFigure 34. Retrieving the Active Time Zone\n\nThe malware calls the GetTimeZoneInformation API to determine the active time zone configured on the infected system.\n\nFigure 35. Retrieving the User's Default Locale\n\nThe malware calls the GetUserDefaultLocaleName API to obtain the user's default locale identifier.\n\nPage 17 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 36. Querying System Battery Information\n\nThe software uses the GetSystemPowerStatus API to query the system's power source status and battery metrics.\n\nFigure 37. Retrieving the Executable Path of a Running Process\n\nThe malware calls the K32GetModuleFileNameExW API to obtain the full path of the target process's executable file.\n\nFigure 38. Retrieving Processor Information from the Registry\n\nThe malware uses the RegOpenKeyExW and RegQueryValueExW APIs to read processor model information from the\n\nWindows Registry. For this purpose, it queries the ProcessorNameString value under the CentralProcessor\\0 key to\n\ndetermine the processor model installed on the system.\n\nFigure 39. Enumerating Display Devices\n\nThe malware collects display hardware information using the EnumDisplayDevicesW and EnumDisplaySettingsW APIs.\n\nThrough these APIs, it obtains information such as installed graphics adapters, connected monitors, screen resolutions, and\n\nother graphics configuration details.\n\nFigure 40. Preparing Network Information\n\nThe malware begins collecting network-related information by creating a dedicated Network Info section within the system\n\nreport. Information related to IP addresses and network configuration is prepared and stored in memory to be sent to the\n\nCommand and Control (C2) server later.\n\nPage 18 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 41. Creating the System Summary Section\n\nAfter collecting network information, the malware creates a System Summary section where additional hardware and\n\noperating system information is stored. This information is later included in the system report to be exfiltrated.\n\nFigure 42. Creating the HWID Section\n\nThe malware combines multiple hardware and operating system attributes to generate a unique Hardware Identifier\n\n(HWID) for the infected system. This identifier allows the C2 server to uniquely identify and track the same victim system\n\nacross different sessions.\n\nFigure 43. Enumerating Running Processes\n\nThe malware uses the CreateToolhelp32Snapshot API to create a snapshot of all processes currently running on the system.\n\nIt then iterates through the process list using the Process32Next API, collecting information such as process names and\n\nProcess IDs (PIDs).\n\nFigure 44. Sending Collected System Information\n\nPage 19 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nAfter collecting system information, running processes, and installed software, the malware encrypts this data using the\n\nRC4 algorithm and then encodes the encrypted output with Base64 before sending it to the Command and Control (C2)\n\ninfrastructure.\n\nFigure 45. Contents of the System_info.txt File\n\nThe collected system information is encrypted with RC4 and encoded with Base64 before leaving the infected system. On\n\nthe C2 side, this data is decrypted to reconstruct the original system_info.txt file. The resulting report provides a\n\ncomprehensive victim profile containing hardware specifications, operating system information, installed software, running\n\nprocesses, network configuration, and details about the system environment.\n\nFigure 46. Opening the Chrome Local State File\n\nThe malware opens Google Chrome's Local State file using the CreateFileW API. After successfully obtaining the file\n\nhandle, it calls the GetFileSizeEx API to determine the file size before processing its contents.\n\nFigure 47. Copying Browser Data to the ProgramData Directory\n\nThe malware copies the contents of the Local State file to a randomly named file under the ProgramData directory. This\n\nfile contains Chrome user configuration data and certain encryption keys.\n\nStolen Browser Data Stolen Browser Data\n\nLocal State\n\nWeb Data\n\nMicrosoft Edge\\Default\\Cookies\n\nTable 17. Stolen Browser Artifacts\n\nCookies\n\nMicrosoft Edge\\Default\\Login Data\n\nkeys\\Microsoft Edge\\v20.txt\n\nPage 20 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 48. Deletion of Temporary Browser Database Files\n\nThe malware targets the Google Chrome Cookies database. It opens the ...\\User Data\\Default\\Network\\Cookies file\n\nlocated in the user's profile directory and checks the \"SQLite format 3\" header to verify that the file is a valid SQLite\n\ndatabase before processing it. After the data is copied and processed, the temporary files created during the operation are\n\ndeleted from the system.\n\nFigure 49. Browser Data Exfiltration\n\nAfter collecting browser data, the malware encrypts the stolen data using RC4 stream encryption and then encodes the\n\nencrypted output with Base64 before transmitting it to the Command and Control (C2) server. The same collection,\n\nencryption, and exfiltration workflow is repeated for all supported web browsers.\n\nFigure 50. Outlook Profile Scanning\n\nThe malware scans Microsoft Outlook profiles registered on the system through the Registry. It prepares Outlook profile\n\npaths for Office 13.0, 14.0, 15.0, and 16.0 versions under the Windows Messaging Subsystem and searches each profile\n\nusing its GUID. It processes the retrieved profile information in memory and saves it to the soft\\Outlook\\outlook.txt file,\n\nthereby collecting profile and configuration data associated with Outlook accounts configured on the system.\n\nPage 21 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nFigure 51. Foxmail Detection\n\nThe malware opens the Software\\Aerofox\\FoxmailPreview Registry key and reads the\n\nRegOpenKeyExA and RegQueryValueExA APIs. It processes the retrieved executable path in memory to determine\n\nwhether the Foxmail email client is installed on the system.\n\nFigure 52. WinSCP Session Scanning\n\nThe malware opens the MartinPrikryl\\WinSCP2\\Sessions Registry key using the\n\nregistered WinSCP sessions using the RegEnumKeyExA API. This allows it to identify\n\npresent on the system and load the stored session information into memory.\n\nFigure 53. Cryptocurrency Wallet Scanning\n\nThe malware iterates through a\n\nparticularly \"Bitcoin Core\"\n\ninformation is processed and added to the result structure.\n\nWallet\n\nArmory Wallet\n\nBinance\n\nBlockstream Green\n\nCoinomi\n\ncryptocurrency wallet list defined in memory. During the loop, each wallet name,\n\n, is passed as a parameter to the relevant functions, while the wallet's file and directory\n\nWallet\n\nAtomic\n\nBitPay\n\nCake Wallet\n\nCopay\n\nPage 22 of 24\n\nExecutable value using the\n\nRegOpenKeyExA API and enumerates\n\nWinSCP connection profiles\n\nWallet\n\nAtomicDEX\n\nBitcoin Core\n\nChia Wallet\n\nDaedalus Mainnet\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nWallet\n\nDash Core\n\nElectrum-LTC\n\nWallet Wallet\n\nDogecoin Electrum\n\nElectron Cash Ethereum\n\nExodus GreenAddress Guarda Desktop\n\nJaxx Desktop Komodo Wallet Ledger Live\n\nLitecoin Core MEW Desktop MultiDoge\n\nMyEtherWallet NOW Wallet Raven Core\n\nStakeCube Trezor Suite Wasabi Wallet\n\nTable 18. Targeted Cryptocurrency Wallets\n\nFigure 54. Collecting Steam Configuration Data\n\nThe malware opens the Software\\Valve\\Steam Registry key using the RegOpenKeyExA API and reads the SteamPath\n\nvalue through the RegQueryValueExA API. It appends the \\config\\ subdirectory to the retrieved Steam installation\n\ndirectory to construct the target path containing Steam configuration files. It then calls file-processing functions on this\n\ndirectory to collect Steam configuration data and prepare it for exfiltration.\n\nFigure 55. Capturing a Screenshot\n\nThe malware converts the desktop image captured using the BitBlt API into a GDI+ bitmap object using the\n\nGdipCreateBitmapFromHBITMAP function. It then creates a memory-based stream using CreateStreamOnHGlobal\n\nand saves the screenshot to this stream in JPEG format through the GdipSaveImageToStream API. The resulting image is\n\nthen sent to the C2 server.\n\nMITRE ATT\u0026CK\n\nPage 23 of 24\n\nhttps://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\nReconnaissance\n\nGather Victim\n\nHost\n\nInformation\n\n(T1592.001)\n\nGather Victim\n\nNetwork\n\nInformation\n\n(T1590.002)\n\n—\n\n—\n\nExecution Persistence\n\nDLL Side-\n\nUser Loading\n\nExecution (T1574.001)\n\n(T1204.002) (configuration-\n\ndependent)\n\nScheduled\nCommand\nTask/Job:\n\nPrivilege\nDefense Evasion\nEscalation\n\nExploitation\n\nfor Privilege\n\nEscalation Obfuscated Files or\n\n(T1068) Information (T1027)\n\n(configuration-\n\ndependent)\n\nand\nScheduled Deobfuscate/Decode\nScripting\nTask — Files or Information\nInterpreter:\n(T1053.005) (T1140)\nAutoIt\n(configuration-\n(T1059.010)\ndependent)\n\nNative API Masquerading\n— —\n(T1106) (T1036.005)\n\nIndicator Removal:\n\n— — — File Deletion\n\nCredential\nDiscovery Collection\nAccess\n\nCredentials System\nScreen\nfrom Web Information\nCapture\nBrowsers Discovery\n(T1113)\n(T1555.003) (T1082)\n\nArchive\nCredentials Process\nCollected\nfrom Password Discovery\nData\nStores (T1555) (T1057)\n(T1560)\n\nCredentials\n\nfrom Windows\nFile and Data from\nCredential\nDirectory Local\nManager\nDiscovery System\n(T1555.004)\n(T1083) (T1005)\n(where\n\napplicable)\n\nCredentials Data from\nQuery\nfrom Web Information\nRegistry\nBrowsers Repositories\n(T1070.004)\n\nTimestomp\n— — — —\n(T1070.006)\n\nVirtualization/Sandbox\n— — — —\nEvasion (T1497)\n\nDynamic API\n— — —\n\nSource: https://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md\n\n—\nResolution (T1027)\n\nPage 24 of 24\n\n(T1012)\n(T1555.003) (T1213)\n\nSoftware\n\nCredentials Discovery:\nArchive via\nfrom Password Security\nUtility\nManagers Software\n(T1560.001)\n(T1555) Discovery\n\n(T1518.001)\n\nPrivate Keys System Data from\n\n(T1555) Owner/User Local\n\n(cryptocurrency Discovery System\n\nwallets) (T1033) (T1005)\n\nSystem Data from\n\nTime Information\n—\nDiscovery Repositories\n\n(T1124) (T1213)","extraction_quality":1,"language":"EN","sources":["Malpedia"],"origins":["web"],"references":["https://github.com/Yavuzhanzgen/StealC-Malware-Analysis/blob/main/Reports/StealC-V2-EN.md"],"report_names":["StealC-V2-EN.md"],"threat_actors":[{"id":"9f101d9c-05ea-48b9-b6f1-168cd6d06d12","created_at":"2023-01-06T13:46:39.396409Z","updated_at":"2026-09-20T02:00:04.40444Z","deleted_at":null,"main_name":"Earth Lusca","aliases":["TAG-22","BRONZE UNIVERSITY","AQUATIC PANDA","Charcoal Typhoon","CHROMIUM","ControlX","Red Dev 10","RedHotel","BountyGlad","Red Scylla"],"source_name":"MISPGALAXY:Earth Lusca","tools":["ShadowPad","POISONPLUG","Barlaiy","Spyder","FunnySwitch","RouterGod","SprySOCKS"],"source_id":"MISPGALAXY","reports":null},{"id":"8941e146-3e7f-4b4e-9b66-c2da052ee6df","created_at":"2023-01-06T13:46:38.402513Z","updated_at":"2026-09-20T02:00:03.499324Z","deleted_at":null,"main_name":"Sandworm","aliases":["ELECTRUM","IRIDIUM","APT44","SANDWORM RELIC","Quedagh","G0034","TeleBots","Blue Echidna","UAC-0113","TEMP.Noble","Seashell Blizzard","UAC-0082","VOODOO BEAR","IRON VIKING","FROZENBARENTS","UAC-0145"],"source_name":"MISPGALAXY:Sandworm","tools":[],"source_id":"MISPGALAXY","reports":null},{"id":"a944f36a-368d-49d4-bc10-548679e9fcf4","created_at":"2026-09-17T02:00:03.699039Z","updated_at":"2026-09-20T02:00:04.00578Z","deleted_at":null,"main_name":"BRONZE UNIVERSITY","aliases":["Aquatic Panda","Aquatic Panda ","CHROMIUM","Charcoal Typhoon","Charcoal Typhoon ","Earth Lusca","Red Dev 10","Red Scylla","RedHotel","Tag-22"],"source_name":"Secureworks:BRONZE UNIVERSITY","tools":["Brute Ratel C4","Cobalt Strike","Fishmaster","FunnySwitch","ShadowPad","SprySOCKS","Spyder","njRAT"],"source_id":"Secureworks","reports":null},{"id":"6abcc917-035c-4e9b-a53f-eaee636749c3","created_at":"2022-10-25T16:07:23.565337Z","updated_at":"2026-09-20T02:00:05.821433Z","deleted_at":null,"main_name":"Earth Lusca","aliases":["Bronze University","Charcoal Typhoon","Chromium","G1006","Red Dev 10","Red Scylla"],"source_name":"ETDA:Earth Lusca","tools":["Agentemis","AntSword","BIOPASS","BIOPASS RAT","BadPotato","Behinder","BleDoor","Cobalt Strike","CobaltStrike","Doraemon","FRP","Fast Reverse Proxy","FunnySwitch","HUC Port Banner Scanner","KTLVdoor","Mimikatz","NBTscan","POISONPLUG.SHADOW","PipeMon","RbDoor","RibDoor","RouterGod","SAMRID","ShadowPad Winnti","SprySOCKS","WinRAR","Winnti","XShellGhost","cobeacon","fscan","lcx","nbtscan"],"source_id":"ETDA","reports":null},{"id":"3a0be4ff-9074-4efd-98e4-47c6a62b14ad","created_at":"2022-10-25T16:07:23.590051Z","updated_at":"2026-09-20T02:00:05.83774Z","deleted_at":null,"main_name":"Energetic Bear","aliases":["ATK 6","Blue Kraken","Crouching Yeti","Dragonfly","Electrum","Energetic Bear","G0035","Ghost Blizzard","Group 24","ITG15","Iron Liberty","Koala Team","TG-4192"],"source_name":"ETDA:Energetic Bear","tools":["Backdoor.Oldrea","CRASHOVERRIDE","Commix","CrackMapExec","CrashOverride","Dirsearch","Dorshel","Fertger","Fuerboos","Goodor","Havex","Havex RAT","Hello EK","Heriplor","Impacket","Industroyer","Karagany","Karagny","LightsOut 2.0","LightsOut EK","Listrix","Oldrea","PEACEPIPE","PHPMailer","PsExec","SMBTrap","Subbrute","Sublist3r","Sysmain","Trojan.Karagany","WSO","Webshell by Orb","Win32/Industroyer","Wpscan","nmap","sqlmap","xFrost"],"source_id":"ETDA","reports":null},{"id":"d53593c3-2819-4af3-bf16-0c39edc64920","created_at":"2022-10-27T08:27:13.212301Z","updated_at":"2026-09-20T02:00:04.268561Z","deleted_at":null,"main_name":"Earth Lusca","aliases":["Earth Lusca","TAG-22","Charcoal Typhoon","CHROMIUM","ControlX"],"source_name":"MITRE:Earth Lusca","tools":["Mimikatz","PowerSploit","Tasklist","certutil","Cobalt Strike","Winnti for Linux","Nltest","NBTscan","ShadowPad"],"source_id":"MITRE","reports":null},{"id":"b3e954e8-8bbb-46f3-84de-d6f12dc7e1a6","created_at":"2022-10-25T15:50:23.339976Z","updated_at":"2026-09-20T02:00:04.045253Z","deleted_at":null,"main_name":"Sandworm Team","aliases":["Sandworm Team","ELECTRUM","Telebots","IRON VIKING","BlackEnergy (Group)","Quedagh","Voodoo Bear","IRIDIUM","Seashell Blizzard","FROZENBARENTS","APT44"],"source_name":"MITRE:Sandworm Team","tools":["Bad Rabbit","Mimikatz","Exaramel for Linux","Exaramel for Windows","GreyEnergy","PsExec","Prestige","P.A.S. Webshell","AcidPour","VPNFilter","Neo-reGeorg","Cyclops Blink","SDelete","Kapeka","AcidRain","Industroyer","Industroyer2","BlackEnergy","Cobalt Strike","NotPetya","KillDisk","PoshC2","Impacket","Invoke-PSImage","Olympic Destroyer"],"source_id":"MITRE","reports":null}],"ts_created_at":1789610607,"ts_updated_at":1789869751,"ts_creation_date":0,"ts_modification_date":0,"files":{"pdf":"https://archive.orkl.eu/f9128ffb075b0991d429db61c8d28bf459fddf4b.pdf","text":"https://archive.orkl.eu/f9128ffb075b0991d429db61c8d28bf459fddf4b.txt","img":"https://archive.orkl.eu/f9128ffb075b0991d429db61c8d28bf459fddf4b.jpg"}},{"id":"32bb8ba2-f936-45ba-b157-42c1cb2b056e","created_at":"2026-09-17T02:02:29.922757Z","updated_at":"2026-09-20T02:01:37.265572Z","deleted_at":null,"sha1_hash":"dd1d80f4a9393afc5ebb4ff77dd25691483b2334","title":"Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs","llm_title":"","authors":"","file_creation_date":"0001-01-01T00:00:00Z","file_modification_date":"0001-01-01T00:00:00Z","file_size":1918675,"plain_text":"https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nFORTIGUARD LABS THREAT RESEARCH\n\nCasbaneiro: A Banking\n\nTrojan with Distributed\n\nData-Receiving Servers\n\nNew Casbaneiro campaign uses geofencing, staged loaders, and distributed\nservers to evade analysis\n\nEnglish\n\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites throughARTICLE CONTENTS\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more informationBy Rachael Liao | September 10, 2026\non how we process personal data.\n\nPrivacy Policy\n\nAffected Platforms: Microsoft Windows\n\nImpacted Users: Microsoft WindowsAccept All\nImpact: The stolen information can be used for future attacks\n\nSeverity Level: High\nCookie Settings\nNeed help? Chat with us!\nIn August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting\n\nusers in Latin America, using phishing emails and PDF files themed around fake invoices\nReject All\nand legal notices as the initial stage.\n\nPage 1 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nCasbaneiro exhibits characteristics common to other malware families targeting financial\n\ninstitutions and users in Latin America, including clipboard injection and the use of fake\n\nwindows to facilitate fraudulent activities. However, our analysis of the recent attack\n\nrevealed several distinctive network behaviors that differentiate this campaign from\n\npreviously observed Casbaneiro behavior.\n\nIn this attack campaign, the malware is delivered via a multi-stage infection chain that\n\nincludes an HTA downloader and an AutoIt loader, with the latter responsible for\n\ninjecting the final payload into a Windows process.\n\nAttack Chain\n\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nFigure 1: Attack flow\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.Initial stage\n\nPrivacy Policy\nThe threat actor uses phishing emails and PDFs to prompt victims to click malicious\n\nlinks. These lures typically evoke urgency or concern, such as fake invoices and legal\n\nnotices, including purported legal proceedings. To enhance credibility and increase the\n\nlikelihood of victim interaction, the emails and PDFs often include the recipient’s email\n\naddress, making the content appear more personalized and legitimate. The country code\nNeed help? Chat with us!\ntop-level domain in the documents further suggests a regional targeting strategy, with\n\nobserved activity indicating a focus on Latin America, including Argentina, Peru,\n\nColombia, and Mexico.\n\nPage 2 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nFigure 2: Phishing PDF files\n\nWebpage\n\nIf the user’s IP address does not originate from the targeted country, the webpage\n\nredirects the user to legitimate websites, such as Google or YouTube. However, if the IP\n\naddress falls within the targeted geographic region, the webpage redirects the user to a\n\npage that contains a Base64-encoded ZIP archive embedded in its JavaScript code. The\n\nJavaScript programmatically initiates the download of the archive, causing the browser\n\nto display its native download notification and creating the appearance of a legitimate\n\nfile download. Upon completion of the download, the webpage redirects the user to a\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionalityblank pag, analyze site usage, and assist in our marketing efe, further reinforcing the appearance of a legitforts. imateThis includes the use of download process.\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.\n\nPrivacy Policy\n\nNeed help? Chat with us!\n\nPage 3 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use ofFigure 3: The geofenced webpage\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nHTA Downloaderlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.The ZIP contains at least one HTA file for the next stage. The HTA references an external\n\nJavaScript resource that retrieves an externally hosted XML-based script package\nPrivacy Policy\ncontaining embedded JScript. The JScript performs additional environment checks\n\nthrough Windows Management Instrumentation (WMI), including sandbox detection and\n\nOS language identification. The script proceeds with the remaining execution only if the\n\ndetected OS language matches one of the languages on the predefined whitelist.\n\nNeed help? Chat with us!\nThe corresponding country/region list is provided below:\n\nPage 4 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nOnce the environment meets these criteria, the malware proceeds with its remaining\n\ntasks. It downloads an AutoIt interpreter, a compiled AutoIt script, and a compressed file\n\nseparately to the directory C:\\{random name}. The AutoIt interpreter is a legitimate\n\nprogram, and the compiled script and compressed file are binary files that require the\n\ninterpreter for execution. By retrieving these components independently, the malware\n\ncan potentially evade static detection mechanisms, as none of the individual files\n\nexhibits malicious behavior when analyzed in isolation. Additionally, because the\n\ncomponents are not packaged together, the likelihood that their relationship and\n\ncombined functionality will be identified through static analysis is reduced.\n\nThe three files are named using random strings, with the compressed file having a crT\n\nsuffix. The suffix serves as a marker that allows the AutoIt script to identify the\n\ncompressed file without relying on a fixed filename. For persistence, it creates an LNK\n\nfile in the Startup folder that executes the AutoIt script through the AutoIt interpreter. In\n\naddition, it creates a folder named {ComputerName}@4{UserName} within the\n\n%PUBLIC% directory, which serves as an infection marker to prevent repeated execution\n\nor reinfection.By clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\nAutoIt Loaderour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more informationOnce executed, it pops up a window that mimics a Windows service, then locates and\non how we process personal data.decompresses the file identified by the crT suffix to extract the final payload. There are\n\ntwo possible injection targets, RegSvcs.exe and mobsync.exe. The malware injects the\nPrivacy Policy\npayload into mobsync.exe only if RegSvcs.exe does not exist.\n\nNeed help? Chat with us!\n\nPage 5 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nFigure 4: The fake Windows service window opened by the AutoIt script\n\nCasbaneiro\n\nInitialization\n\nUpon execution, Casbaneiro decrypts required strings, including cryptocurrency\n\naddresses, global ID, and a data exfiltration URL. Casbaneiro uses the same decryption\n\nalgorithm as Ousaban. The decryption key and encrypted strings are split into multiple\n\nfragments, which are concatenated at runtime whenever the malware needs to decrypt\n\nand use a specific string. During initialization, the malware creates a mutex named\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\nGlobolID-4465173{Username} to prevent concurrent execution. It also checks the\ncookies and similar technologies to show you personalized advertising on other websites throughsystem’s default language and proceeds only if it is not German, French, or English.\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\nAfterward, the malware constructs a string by concatenating the computer name,\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.username, and executable name, then computes its MD5 hash for later use. The malware\n\ncollects email addresses from the victim’s address book, as well as sender and recipient\nPrivacy Policy\ninformation from emails stored in Microsoft Outlook. It then transmits the collected data\n\nin unencrypted form to a data exfiltration URL. Two URLs are generated for this purpose\n\nusing different methods: one is derived through decryption, while the other is\n\nconstructed through string concatenation. The malware also creates an infection marker\n\nto track email-stealing activity. This marker is stored as a file named .Outlook in the\nNeed help? Chat with us!\n%APPDATA% directory.\n\nPage 6 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nFigure 5: HTTP POST request containing exfiltrated data\n\nInformation Collection \u0026 403 Forbidden\n\nNotably, Casbaneiro sends base64-encoded victim information to the second server,\n\nwhich responds with an HTTP 403 Forbidden status. If the server returns any status\n\nother than 403, the malware retries the request. This behavior may mislead analysts into\n\nconcluding that the C2 infrastructure is unavailable, potentially leading them to overlook\n\nthe actual C2 server.\n\nCasbaneiro communicates with the C2 only when the victim visits a targeted bank\n\nwebsite via a web browser. Two infection markers are created only after an HTTP 403\n\nresponse is received, thereby preventing the same activity from being repeated and\n\nreducing the likelihood of detection. One is a folder named after the MD5 hash of the\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nvictim’s information, created in %TEMP%. The other is a registry key named after the\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\nMD5 hash in HKCU\\SOFTWARE.\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.\n\nPrivacy Policy\n\nNeed help? Chat with us!\n\nPage 7 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nFigure 6: The data sent to the server is base64 encoded.\n\nComment and Control\n\nThe C2 tasks include keyboard control, clipboard pasting, file execution, command\n\nexecution, and several tasks related to the fake window targeting the specified banks.\n\nThe initial C2 packet is transmitted when the victim accesses a webpage associated\n\nwith a targeted bank listed in the appendix. The following lists the victim information\n\ntransmitted to the third server.\n\nBy distributing stolen data across multiple servers and triggering communications at\n\ndifferent times, the malware obscures the relationship between network connections,\n\ncomplicating the analysis of network logs. This is further compounded by the fact that\n\nthe actual C2 communication is triggered only under specific conditions, such as when\n\nthe victim accesses a targeted banking website.\n\nIn addition, we captured the following malformed HTTP packets during our analysis. Two\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nnotable anomalies were observed: the absence of the Host header and an unusually\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\nlarge Content-Length value, with the corresponding request body delivered\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nincrementally across numerous small packets. These deviations from standard HTTP\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\nformatting may be intentional and could serve to evade network-based detection or\napply only to your current browser/device. Please also see our Privacy Policy for more information\ncomplicate traffic inspection and analysis.\non how we process personal data.\n\nPrivacy Policy\n\nNeed help? Chat with us!\n\nPage 8 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nFigure 7: The malformed HTTP request\n\nConclusion\n\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nIn this article, we analyzed an attack campaign targeting users in Latin America that uses\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\nCasbaneiro. The campaign uses multiple restrictions to hide the malware from analysis\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\ntools, including the download page, the HTA downloader, and Casbaneiro itself.\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more information\nIn addition to its conventional features, Casbaneiro incorporates several techniques\non how we process personal data.\ndesigned to hinder analysis, including an endpoint that deliberately returns HTTP 403\nPrivacy Policyresponses and the transmission of different types of stolen data to separate servers.\n\nCasbaneiro also uses a targeted activation mechanism. Only when the victim accesses\n\nwebsites related to targeted banks through a web browser does the malware send\n\ninformation about the infected computer to the server and initiate C2 communication.\n\nThese techniques can make the malware and its infrastructure appear inactive or\n\ninaccessible to automated analysis tools, helping the threat actor evade analysis and\nNeed help? Chat with us!\ndetection. FortiGuard will continue to monitor this attack campaign and provide\n\nappropriate protection as necessary.\n\nPage 9 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nFortinet Protections\n\nThe malware described in this report is detected and blocked by FortiGuard Antivirus as:\n\nPDF/Phishing.5BB0!tr\n\nJS/Phishing.IBP!tr\n\nW32/Casbaneiro.EN!tr.spy\n\nFortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service.\n\nThe FortiGuard AntiVirus engine is part of each of these solutions. As a result, customers\n\nwho have these products with up-to-date protections are protected.\n\nFortiMail recognizes the phishing email as “virus detected.” In addition, real-time anti-\n\nphishing provided by FortiSandbox embedded in Fortinet’s FortiMail, web filtering, and\n\nantivirus solutions provides advanced protection against both known and unknown\n\nphishing attempts.\n\nThe FortiGuard CDR (Content Disarm and Reconstruction) service, which runs on both\n\nFortiGate and FortiMail, can disarm the malicious macros in the document.\n\nWe also suggest that organizations go through Fortinet’s free NSE training module: FCF\n\nFortinet Certified Fundamentals. This module is designed to help end users learn how to\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nidentify and protect themselves from phishing attacks.\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\nFortiGuard IP Reputation and Anti-Botnet Security Service proactively block these\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Yattacks by aggregating malicious source IP data from the Fortinet distributedour choice will network of\napply only to your current browser/device. Please also see our Privacy Policy for more informationthreat sensors, CERTs, MITRE, cooperative competitors, and other global sources that\non how we process personal data.\ncollaborate to provide up-to-date threat intelligence about hostile sources.\nPrivacy Policy\nThe FortiPhish Phishing Simulation Service, together with Fortinet’s Security Awareness\n\nand Training Service, uses real-world phishing scenarios to train and test employees on\n\ncommon social engineering tactics. By improving users’ ability to recognize and respond\n\nto suspicious content—especially during high-risk periods of distraction or urgency—\n\nthese services help reduce the risk of successful phishing and malware attacks.\nNeed help? Chat with us!\n\nIf you believe this or any other cybersecurity threat has impacted your organization,\n\nplease contact our Global FortiGuard Incident Response Team.\n\nPage 10 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nIOCs\n\nPDF\n\n6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73\n\n40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd\n\nbf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8\n\n943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280\n\n711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859\n\nd910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365\n\n47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95\n\nd13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85\n\nd04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c\n\n1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed\n\nBy clicking \"Accept 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5\nAll\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\nea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.\n0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5\nPrivacy Policy\n\nc521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e\n\n0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a\n\nEmail Need help? Chat with us!\n\ndebe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556ea\n\nba2d71057\n\nPage 11 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\neaec8c6950f394ad5dcd271aa86f08cb2b837\n\n057244390\n\n995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5\n\ne861fac457\n\n918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d043\n\nd08844f62\n\nbe5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06c\n\na0f3c056\n\ndc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb0\n\n2f0bd59d565\n\nHTA\n\n4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337\n\n85767416f8d1e73833ccaa193263d1198857308b3a\n\nf1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27\n\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nc477bdfae91e3df9be29e9eeba785467\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\n6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4our partners. To accept only necessary cookies, select “Reject \nlink, which contains details on specific cookies, categories, and preference options. Y\napply only to your current browser/device. Please also see our Privacy Policy for more information4540c3af3b1d8c52256f4580dd4d002fadb8c5ff\non how we process personal data.\n92a1428e125f33de012c7f52fb0827be3d7\nPrivacy Policy\n\ne57409c5e1f8287900c1c3b3e8c099cef537\n\n5a76669ec410d0b3e21112a4a6fd3207976b299ee27\n\n8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33\n\n99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da\n\n4203ecc67015af7ca6\n\nd756e6915044\n\n1185e6f4ebc4164db8584f\n\ne246b\n\naff294f5250c2eed406765032cb68756\n\nAll.” You can visit the Cookie Settings\n\n4e32e6a41fdf508455c5b697\n\ne90e38a0e38083181f8c3312adc9c\n\na02949315eb768c88906b0c65add\n\nc5fc3d42f2673170ab95e\n\nNeed help? Chat with\n\n179f3cd5faf81b1\n\nPage 12 of 18\n\nour choice will\n\nus!\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\n875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b\n\nbd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01\n\na42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7\n\n7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707\n\n6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093\n\n51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c\n\n5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717\n\n71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b\n\nc2be456\n\ne81bad5054cf4e8\n\nd0ff02\n\nDomain\n\n128 [.] 200[.] 178 [.] 68 [.]host[.]secureserver[.]net\n\n13[.] 189 [.] 202 [.] 64[.]host[.]secureserver[.]net\n\n116 [.] 181[.] 62 [.] 50[.]host[.]secureserver[.]net\n\n48 [.] 178 [.] 169 [.] 192 [.]host[.]secureserver[.]netBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through115 [.] 201[.] 178 [.] 68 [.]host[.]secureserver[.]net\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\n181[.] 202 [.] 178 [.] 68 [.]host[.]secureserver[.]net\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.\n135 [.] 201[.] 178 [.] 68 [.]host[.]secureserver[.]net\nPrivacy Policy\n85 [.] 182 [.] 62 [.] 50[.]host[.]secureserver[.]net\n\n162 [.] 201[.] 178 [.] 68 [.]host[.]secureserver[.]net\n\n129 [.] 202 [.] 178 [.] 68 [.]host[.]secureserver[.]net\nNeed help? Chat with us!\n76 [.] 180[.] 62 [.] 50[.]host[.]secureserver[.]net\n\ngexwalltool[.]com\n\nPage 13 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nx-wolverine[.]servebbs[.]com\n\nIP\n\n72 [.] 167[.] 48 [.] 63\n\n209 [.] 99 [.] 188 [.] 28\n\nAutoIt script\n\nfc820eeb054c781693eca78fed1c418f12b27da2c7c7\n\nf76d09cbd455ce18765591b9efa3bde0d31358b6321f7\n\nCasbaneiro payload\n\n7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027\n\nCryptocurrency address\n\n0xb4c12078448fdef1f8881a55aab5c81fa194095c\n\nbc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. TAppendixo accept only necessary cookies, select “Reject \nlink, which contains details on specific cookies, categories, and preference options. Y\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.Bank list\n\nPrivacy Policy\n\nPage 14 of 18\n\ne73281eb07b25cc7d910\n\na10fc2e04f65d7407ba\n\nc5ebca3fc8\n\nAll.” You can visit the Cookie Settings\nour choice will\n\nNeed help? Chat with us!\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.\n\nPrivacy PolicyRelated Posts\n\nNeed help? Chat with us!\n\nPage 15 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nTHREAT RESEARCH\n\nHavoc: SharePoint with Microsoft Graph API turns into FUD C2\n\nTHREAT RESEARCH\n\nFortinet Identifies Malicious Packages in the Wild: Insights and Trends from November\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\n2024 Onward\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” You can visit the Cookie Settings\nlink, which contains details on specific cookies, categories, and preference options. Your choice will\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.\n\nPrivacy Policy\n\nTHREAT RESEARCH Need help? Chat with us!\nAnalyzing ELF/Sshdinjector.A!tr with a Human and Artificial Analyst\n\nPage 16 of 18\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nNews \u0026 Articles\nNews Releases\n\nNews Articles\n\nSecurity Research\nThreat Research\n\nFortiGuard Labs\n\nThreat Map\n\nRansomware Prevention\n\nConnect With Us\nFortinet Community\n\nPartner Portal\n\nInvestor Relations\n\nProduct Certifications\n\nBy clicking \"Accept Company All\", you are consenting to the use of cookies on your device to enhance site\nfunctionalityUs, analyze site usage, and assist in our marketing efforts. This includes the use ofAbout \ncookies and similar technologies to show you personalized advertising on other websites through\nExec Mgmt\nour partners. To accept only necessary cookies, select “Reject \nCareerslink, which contains details on specific cookies, categories, and preference options. Y\napply only to your current browser/device. Please also see our Privacy Policy for more informationTraining\non how we process personal data.Events\n\nIndustry Awards\nPrivacy Policy\nSocial Responsibility\n\nCyberGlossary\n\nSitemap\n\nBlog Sitemap\n\nPage 17 of 18\n\nAll.” You can visit the Cookie Settings\nour choice will\n\nNeed help? Chat with us!\n\nhttps://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\n\nCopyright © 2026 Fortinet, Inc. All Rights Reserved Terms\n\nPolicy | Cookie Settings\n\nFORTINET: Cybersecurity everywhere\n\nAlso of Interest:\n\nWhat is Fortibleed?\n\nPay Ransomware Settlements?\n\nLife at Fortinet\n\nFortinet CVE Analysis\n\nBy clicking \"Accept All\", you are consenting to the use of cookies on your device to enhance site\nfunctionality, analyze site usage, and assist in our marketing efforts. This includes the use of\ncookies and similar technologies to show you personalized advertising on other websites through\nour partners. To accept only necessary cookies, select “Reject All.” Y\nlink, which contains details on specific cookies, categories, and preference options. Y\napply only to your current browser/device. Please also see our Privacy Policy for more information\non how we process personal data.\n\nPrivacy Policy\n\nPage 18 of 18\n\nof Services Privacy\n\nyou need it\n\nou can visit the Cookie Settings\nour choice will\n\nNeed help? Chat with us!","extraction_quality":1,"language":"EN","sources":["Malpedia"],"origins":["web"],"references":["https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers"],"report_names":["casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers"],"threat_actors":[],"ts_created_at":1789610549,"ts_updated_at":1789869697,"ts_creation_date":0,"ts_modification_date":0,"files":{"pdf":"https://archive.orkl.eu/dd1d80f4a9393afc5ebb4ff77dd25691483b2334.pdf","text":"https://archive.orkl.eu/dd1d80f4a9393afc5ebb4ff77dd25691483b2334.txt","img":"https://archive.orkl.eu/dd1d80f4a9393afc5ebb4ff77dd25691483b2334.jpg"}},{"id":"e27f5989-4e97-473b-9b66-0a63fcd5f340","created_at":"2026-09-15T02:03:55.912156Z","updated_at":"2026-09-20T02:01:31.046868Z","deleted_at":null,"sha1_hash":"30230640d02274696585ba21e4ece09908a664ad","title":"Koktevrat – wieloetapowy Android RAT dystrybuowany pod przykrywką aplikacji MandatGO","llm_title":"","authors":"","file_creation_date":"0001-01-01T00:00:00Z","file_modification_date":"0001-01-01T00:00:00Z","file_size":1680819,"plain_text":"https://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nKoktevrat – wieloetapowy Android RAT dystrybuowany pod\n\nprzykrywką aplikacji MandatGO\n\nBy Zespół CERT Orange Polska\n\nPublished: 2026-09-09 · Archived: 2026-09-15 02:01:38 UTC\n\nNieistniejąca aplikacja rządowa, reklama na Facebooku i obietnica prostego sposobu na opłacenie mandatu.\n\nTak zaczyna się infekcja, której kolejne etapy prowadzą od zwykłego pliku APK do pełnoprawnego Android\n\nRAT-a. Analiza próbki pokazuje, że atakujący nie ograniczyli się do kradzieży danych. Malware zapewnia\n\noperatorowi szeroki zestaw funkcji pozwalających na zdalne pozyskiwanie informacji, wykonywanie działań\n\nna urządzeniu i utrzymywanie komunikacji z infrastrukturą C2.\n\nAnalizowana próbka została pozyskana w ramach kampanii wykorzystującej aplikację MandatGO, przedstawianą\n\nużytkownikom jako narzędzie związane z obsługą mandatów.\n\nPage 1 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nReklama zachęcająca do zainstalowania aplikacji\n\nPage 2 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nDystrybucja odbywała się za pośrednictwem reklamy na Facebooku, a użytkownik był kierowany do strony fb-\n\nmarket-play[.]cc, z której mógł pobrać plik APK. Aplikacja MandatGO okazała się pierwszym etapem\n\nwieloetapowego łańcucha prowadzącego do instalacji Android RAT-a.\n\nFanpage na Facebooku dystrybuujący złośliwą aplikację\n\nNa potrzeby analizy badaną rodzinę nazwaliśmy koktevrat. Nazwa pochodzi od ciągu koktevran_channel,\n\nwykorzystywanego przez malware podczas tworzenia kanału powiadomień Androida. Nie znaleziono\n\nwystarczających przesłanek pozwalających przypisać próbkę do znanej rodziny malware.\n\nNajważniejsze cechy koktevrat to: wieloetapowe ładowanie kodu, wykorzystanie Accessibility Service, komunikacja\n\nC2 wspierana przez Firebase Cloud Messaging (FCM) oraz szeroki zestaw poleceń umożliwiających operatorowi\n\nzdalną interakcję z urządzeniem.\n\nStage 1. Dropper\n\nPierwszy APK prezentuje się jako aplikacja MandatGO, ale jego głównym zadaniem jest dostarczenie kolejnego\n\nkomponentu. Manifest zawiera m.in.  REQUEST_INSTALL_PACKAGES , a kod właściwej aplikacji jest częściowo ukryty\n\nprzed analizą statyczną.\n\nPage 3 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nDropper wykorzystuje dynamiczne ładowanie DEX oraz deszyfrowanie zasobów w czasie działania. Obfuskacja\n\nobejmuje również zakodowane ciągi znaków, refleksję Javy i pozorny kod utrudniający analizę. W jednym z\n\nmechanizmów wykorzystano XOR z trzybajtowym kluczem [32, 17, 46].\n\nPo wykonaniu pierwszego etapu odszyfrowywany jest kolejny komponent – wudEMR.apk. Oznacza to, że APK\n\ndostarczony użytkownikowi nie zawiera wprost pełnej funkcjonalności RAT-a. Istotne elementy pojawiają się dopiero\n\npo wykonaniu droppera.\n\nStage 2: właściwy Android RAT\n\nDrugi komponent zachowuje tę samą nazwę i ikonę co MandatGO, ale jego funkcja jest już zupełnie inna. Pakiet\n\ncom.kowo.ciligeci  zawiera właściwą funkcjonalność koktevrat.\n\nPodobnie jak w pierwszym etapie, kod został ukryty w zasobie  uoN.css . Plik zawiera zaszyfrowany payload, który\n\njest odszyfrowywany przy użyciu RC4 z kluczem  iOZ , a następnie dynamicznie ładowany. Zaciemnianie kodu\n\nzostało zastosowane na obu poziomach łańcucha infekcji.\n\nManifest Stage 2 wskazuje już bezpośrednio na charakter komponentu. Aplikacja posiada m.in.  READ_SMS ,\n\nQUERY_ALL_PACKAGES ,  INTERNET  oraz  WAKE_LOCK . Właściwe możliwości RAT-a wynikają jednak przede\n\nwszystkim z wykorzystania Accessibility Service.\n\nArchitektura drugiego etapu składa się z kilku usług działających w tle oraz odbiornika zdarzeń. Komunikacja i\n\naktywacja funkcji są rozdzielone pomiędzy komponent C2  JyfNnJyj  oraz usługę Accessibility  GtVyayDo . Taki\n\npodział pozwala oddzielić odbieranie poleceń od ich wykonywania.\n\nAccessibility Service jako mechanizm wykonawczy\n\nGtVyayDo  stanowi jeden z najważniejszych komponentów koktevrat. Po uzyskaniu przez malware odpowiedniego\n\nuprawnienia może odbierać zdarzenia Androida oraz wykonywać operacje za pośrednictwem mechanizmów\n\ndostępności.\n\nPage 4 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nEkran włączający usługi dostępności (Accessibility Services).\n\nPage 5 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nZakres obsługiwanych poleceń obejmuje m.in.  launch_app ,  action_home ,  action_recents ,  lock_screen ,\n\nunlock_screen ,  set_text ,  clear_input  oraz  key_press . Operator może więc uruchamiać aplikacje,\n\nwykonywać akcje systemowe i wprowadzać dane do elementów interfejsu.\n\nKoktevrat obsługuje również schowek poprzez  clipboard  i  clear_clipboard . Pozwala to pozyskiwać informacje\n\nkopiowane przez użytkownika oraz usuwać ich zawartość. Kolejnym elementem są nakładki. Polecenia\n\ninject_overlay ,  disable_overlay ,  show_klock ,  hide_klock ,  Show_update_screen  i  hide_update_screen\n\npozwalają malware wyświetlać własne elementy nad aplikacjami. W połączeniu z możliwością wprowadzania tekstu\n\ndaje to operatorowi możliwość wpływania na przebieg interakcji użytkownika z aplikacjami.\n\nW kodzie zidentyfikowano również  olop_maybe_set  oraz  olop_app_set , związane z mechanizmem keyloggingu.\n\nPozwalają one sterować rejestrowaniem aktywności i ograniczać je do określonych aplikacji.\n\nPo uzyskaniu dostępu do Accessibility Service malware podejmuje również działania utrudniające użytkownikowi\n\nprzerwanie procesu konfiguracji. W analizowanym przebiegu uruchamiana jest nakładka, a przez około 45 sekund\n\nwykonywana jest cyklicznie akcja  ACTION_BACK .\n\nAccessibility Service nie jest więc pojedynczą funkcją koktevrat, ale komponentem sterującym, który pozwala\n\nwykorzystać pozostałe możliwości RAT-a w kontekście urządzenia i aktywności użytkownika.\n\nZakres funkcjonalny RAT-a\n\nLista poleceń pokazuje, że koktevrat został zaprojektowany jako pełnoprawne narzędzie zdalnego dostępu, a nie\n\nwyłącznie infostealer.\n\nWśród zidentyfikowanych funkcji znajdują się:\n\nget_sms  – pobieranie wiadomości SMS,\n\nget_apps  – enumeracja zainstalowanych aplikacji,\n\nclipboard / clear_clipboard  – odczyt i czyszczenie schowka,\n\nlaunch_app  – uruchamianie aplikacji,\n\nset_text / clear_input  – wprowadzanie i usuwanie danych,\n\nkey_press  – wykonywanie operacji odpowiadających zdarzeniom klawiatury,\n\ninject_overlay / disable_overlay  – obsługa nakładek,\n\nlock_screen / unlock_screen  – blokowanie i odblokowanie ekranu,\n\nolop_maybe_set / olop_app_set  – sterowanie keyloggingiem.\n\nKomponenty oraz komunikacja aplikacji.\n\nPage 6 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nOsobną grupę stanowią funkcje związane z utrzymaniem dostępu i ograniczaniem możliwości usunięcia malware,\n\nm.in.  protect_on ,  protect_off  oraz  gp_off . Dostępne są również polecenia umożliwiające zmianę ustawień\n\nurządzenia, takie jak  battery_opt ,  brightness_perm  czy  need_admin .\n\nTak szeroki zestaw funkcji wskazuje, że operator może traktować zainfekowane urządzenie nie tylko jako źródło\n\ndanych, ale jako zdalnie sterowany punkt końcowy.\n\nC2: Firebase jako mechanizm sygnalizacji i zdalnego sterowania\n\nWarstwa komunikacyjna koktevrat łączy klasyczną komunikację z serwerem C2 z Firebase Cloud Messaging (FCM).\n\nZa jej obsługę odpowiada przede wszystkim  JyfNnJyj .\n\nPodczas inicjalizacji malware pobiera FCM registration token urządzenia i przekazuje go do infrastruktury C2 za\n\npomocą send_token. Token może w ten sposób służyć jako identyfikator konkretnej instalacji. W kodzie widoczne są\n\nrównież akcje  ACTION_CONNECT ,  ACTION_DISCONNECT ,  ACTION_CHECKIN ,  ACTION_HEARTBEAT  oraz\n\nACTION_REPORT_TOKEN .\n\nFCM pełni przy tym rolę mechanizmu sygnalizacji i wybudzania. Malware nie musi utrzymywać przez cały czas\n\naktywnego kanału komunikacyjnego — może zostać pobudzone przez wiadomość push. Równolegle  AlarmManager\n\nplanuje okresowe uruchomienie komponentu C2. W analizowanej próbce heartbeat ustawiono na około cztery\n\ngodziny.\n\nW kodzie zapisano dwie domeny C2:\n\nstreams-tv[.]lol\n\nstream-plus[.]lat\n\nPróbka zawiera również mechanizm DGA, zmieniający generowane domeny w dziesięciodniowych interwałach.\n\nUtrudnia to skuteczne blokowanie infrastruktury wyłącznie na podstawie statycznej listy domen.\n\nWarstwa C2 nie służy wyłącznie do raportowania statusu urządzenia. Otrzymane polecenia są przekazywane do\n\nkomponentów wykonawczych, m.in. przez intent  com.kowo.ciligeci.COMMAND , obsługiwany przez\n\nGtVyayDo.handleServerCommand .\n\nPage 7 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nKod odpowiadający za generowanie nazw domenowych (implementacja DGA).\n\nTunelowanie ruchu\n\nInteresującą funkcją jest obsługa tunelu TCP poprzez  proxy_open ,  proxy_data  i  proxy_close . Mechanizm\n\npozwala przekazywać ruch sieciowy przez zainfekowane urządzenie, rozszerzając rolę C2 poza zwykłą wymianę\n\nkomend i danych.\n\nW kodzie widoczna jest konfiguracja lokalnego interfejsu z adresem  10.0.0.2/32  oraz trasą obejmującą\n\n0.0.0.0/0 . Wskazuje to na próbę utworzenia routowanego kanału dla ruchu przechodzącego przez implant.\n\nArchitektura koktevrat wykorzystuje więc kilka mechanizmów jednocześnie: C2 odpowiada za wymianę danych i\n\npoleceń, FCM za sygnalizację i wybudzanie, a AlarmManager za okresową aktywność komponentu\n\nkomunikacyjnego.\n\nUtrzymanie dostępu i defense evasion\n\nKoktevrat zawiera również funkcje mające utrudnić użytkownikowi usunięcie malware lub ograniczyć możliwość\n\njego wykrycia. Polecenia  protect_on  i  protect_off  sterują mechanizmem ochrony przed usunięciem, natomiast\n\ngp_off  jest przeznaczone do wyłączenia Google Play Protect.\n\nDodatkowe polecenia pozwalają otwierać odpowiednie ekrany ustawień Androida, m.in. w celu uzyskania kolejnych\n\nuprawnień. W połączeniu z Accessibility Service i możliwością sterowania interfejsem tworzy to mechanizm, w\n\nktórym malware może aktywnie prowadzić urządzenie przez wymagany proces konfiguracji.\n\nIstotną cechą jest również wielowarstwowe ukrywanie kodu. Zarówno dropper, jak i właściwy RAT wykorzystują\n\nszyfrowanie payloadu, dynamiczne ładowanie i obfuskację. Oznacza to, że część najważniejszych artefaktów może\n\nbyć niewidoczna podczas analizy samego dostarczonego APK.\n\nThreat Hunting: najważniejsze artefakty\n\nNajbardziej oczywistymi IOC są domeny C2  streams-tv[.]lol  i  stream-plus[.]lat , jednak ze względu na\n\nwykorzystanie DGA nie powinny być jedyną podstawą detekcji sieciowej.\n\nWarto wyszukiwać również:\n\npakiet  com.kowo.ciligeci ,\n\nkanał powiadomień  koktevran_channel ,\n\npliki  uoN.css  i  uoN.apk ,\n\naplikację wykorzystującą jednocześnie Accessibility Service,  READ_SMS  i  QUERY_ALL_PACKAGES ,\n\naktywność FCM połączoną z podejrzaną aplikacją,\n\nnietypowe operacje  proxy_open ,  proxy_data  i  proxy_close ,\n\nkonfigurację routingu związaną z  10.0.0.2/32 .\n\nDostępne są również hashe analizowanych komponentów:\n\nPage 8 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nKomponent Artefakt SHA-256\n\nStage 1 femam.apk f2042077e2d9fad0ad69e76e706311b3f690e0338ba4765491c4ed0257ad1189\n\nStage 1\nwudEMR.apk 568f1067735bb98185b9191998f798b6d59157673ca99446ce268f3ef6070154\npayload\n\nStage 2 kowo.apk 6b7b09aa12a08951e822e6ab0e08bce4e4bf7b1ecd51bf9fe095cd06a7a445e3\n\nStage 2\nuoN.apk 7c24a56dcacc028648caafba5a209d0488db15412a2c22ac586db940710b5048\npayload\n\nNajwiększą wartość detekcyjną daje jednak korelacja kilku niezależnych artefaktów. Połączenie podejrzanej aplikacji\n\nz Accessibility Service, aktywnością FCM, charakterystycznym kanałem powiadomień i komunikacją z infrastrukturą\n\nC2 stanowi znacznie silniejszy sygnał niż pojedyncza domena lub uprawnienie.\n\nKoktevrat na tle znanych rodzin Android RAT\n\nPod względem funkcjonalnym koktevrat wpisuje się w znany model Android malware wykorzystującego\n\nAccessibility Service do uzyskania szerokiego dostępu do urządzenia. Podobne techniki były wykorzystywane m.in.\n\nprzez FluBot, Cerberus i SpyNote.\n\nNajbliższym porównaniem funkcjonalnym jest FluBot. Obie rodziny łączą Accessibility z obsługą SMS,\n\nrejestrowaniem aktywności użytkownika, nakładkami oraz mechanizmami utrudniającymi wykrycie lub usunięcie\n\nmalware. FluBot posiadał również funkcje proxy i możliwość wyłączenia Google Play Protect. Podobieństwo dotyczy\n\njednak przede wszystkim zestawu technik – nie ma podstaw, aby traktować koktevrat jako wariant FluBota. Podobny\n\nmodel wykorzystuje również Cerberus, który stosował Accessibility do obserwowania zawartości ekranu i\n\nwykonywania operacji w imieniu użytkownika. Koktevrat rozwija ten model o wieloetapowy loader, FCM jako\n\nmechanizm sygnalizacji, DGA oraz tunelowanie ruchu.\n\nZ kolei SpyNote stanowi dobre porównanie z punktu widzenia klasyfikacji. Zakres funkcji koktevrat jest bliższy\n\npełnoprawnemu Android RAT niż malware skoncentrowanemu wyłącznie na kradzieży danych uwierzytelniających\n\nlub atakach na aplikacje finansowe.\n\nNie ma obecnie wystarczających podstaw, aby przypisać koktevrat do FluBot, Cerberusa, SpyNote lub innej znanej\n\nrodziny. Podobieństwa należy traktować jako analogie funkcjonalne, a nie atrybucję.\n\nPodsumowanie\n\nKoktevrat jest wieloetapowym Android RAT-em, którego możliwości wynikają z połączenia kilku dobrze znanych\n\nmechanizmów: ukrytego ładowania kodu, Accessibility Service, komunikacji C2 wspieranej przez FCM oraz\n\nszerokiego zestawu poleceń operatorskich.\n\nNajważniejszym elementem architektury jest połączenie warstwy komunikacyjnej z Accessibility Service. C2\n\ndostarcza instrukcje, natomiast komponent wykonawczy może wykorzystać uprawnienia Androida do pozyskiwania\n\ndanych, wykonywania operacji na urządzeniu, obsługi nakładek czy rejestrowania aktywności użytkownika.\n\nPage 9 of 10\n\nhttps://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nArchitektura komunikacyjna zwiększa odporność implantu: FCM może służyć do jego wybudzania, AlarmManager\n\nzapewnia okresową aktywność, DGA utrudnia blokowanie infrastruktury, a funkcje proxy pozwalają wykorzystać\n\nurządzenie jako pośrednika dla ruchu sieciowego.\n\nNajważniejszy wniosek z analizy jest jednak szerszy: detekcja tego typu zagrożeń nie powinna opierać się wyłącznie\n\nna hashach czy domenach C2. Znacznie większą wartość daje korelacja charakterystycznej aplikacji, uprawnień,\n\nAccessibility Service, aktywności FCM oraz zachowania odpowiadającego funkcjom RAT-a.\n\nKoktevrat pokazuje tym samym, jak legalne mechanizmy Androida mogą zostać połączone w spójny łańcuch\n\nzapewniający operatorowi zdalny dostęp, możliwość kradzieży danych i długotrwałe utrzymanie kontroli nad\n\nurządzeniem.\n\nIreneusz Tarnowski\n\nOlaf Grzybowski\n\nSource: https://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/\n\nPage 10 of 10","extraction_quality":1,"language":"PL","sources":["Malpedia"],"origins":["web"],"references":["https://cert.orange.pl/aktualnosci/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo/"],"report_names":["koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywka-aplikacji-mandatgo"],"threat_actors":[],"ts_created_at":1789437835,"ts_updated_at":1789869691,"ts_creation_date":0,"ts_modification_date":0,"files":{"pdf":"https://archive.orkl.eu/30230640d02274696585ba21e4ece09908a664ad.pdf","text":"https://archive.orkl.eu/30230640d02274696585ba21e4ece09908a664ad.txt","img":"https://archive.orkl.eu/30230640d02274696585ba21e4ece09908a664ad.jpg"}},{"id":"b328f7cb-c7ca-4ef7-938c-3b91e60769f6","created_at":"2026-09-15T02:03:46.251029Z","updated_at":"2026-09-20T02:01:20.148078Z","deleted_at":null,"sha1_hash":"be388fb0179fa9ebe4300fd25a1874ebd04bc0c2","title":"Ping32 RMM and ValleyRAT","llm_title":"","authors":"","file_creation_date":"0001-01-01T00:00:00Z","file_modification_date":"0001-01-01T00:00:00Z","file_size":320933,"plain_text":"Ping32 RMM and V\n\nBy Erik Hjelmvik\n\nPublished: 2026-06-25 · Archived: 2026-09-15 02:02:03 UTC\n\n,\n\nThursday, 25 June 2026 09:27:00 (UTC/GMT)\n\nhttps://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\nalleyRAT\n\nFareed Radzi recently blogged about a malware campaign observed earlier in June by Kaspersky’\n\nThe malware campaign embedded malicious code in VBScripts, which were distributed through WhatsApp DMs.\n\ns GReAT team.\n\nPage 1 of 7\n\nhttps://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\nThe VBScript then dropped the legitimate Remote Monitoring and Management (RMM) tool ManageEngine\n\nEndpoint Central.\n\nFareed included the IOCs for the following Endpoint Central server IP addresses:\n\n202.61.160.208\n\n202.61.160.202\n\n202.61.160.201\n\n202.61.160.160\n\n202.61.160.137\n\n38.55.151.63\n\nHe also noted a link to ValleyRAT:\n\nNotably, 202.61.160[.]201 had previously been observed as command-and-control infrastructure\n\nassociated with ValleyRAT and Gh0st RAT activity. Although the overlap raises the possibility of the\n\nVBS campaign being linked to the operator of these known malware families, the available evidence is\n\ninsufficient to confidently attribute the campaign to a known threat actor.\n\nAttribution is difficult, so it makes sense not to call out any specific threat actor just because of a single\n\noverlapping IP address. Nevertheless, the threat actor that typically comes to mind when talking about ValleyRAT\n\nis Silver Fox (银狐).\n\nRetrohunting in Sandboxes\n\nI searched various online sandboxes for the IP addresses and MD5 hashes that were published in Fareed's blog\n\npost. To my delight I found plenty of samples on ANY.RUN as well as Triage. But what was even more interesting\n\nwas the sandbox executions on Triage for the sample with MD5 hash d43fdaa1f0ee09d7e5f0f94ee9df7b6c. One of\n\nthe known filenames for this sample was \"Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe\n\naus..vbs\".\n\nSample executions on Recorded Future Triage Sandbox:\n\nhttps://tria.ge/260325-z4xp4sew7y\n\nhttps://tria.ge/260325-z763ysex41\n\nI can’t determine how this sample was originally connected to the ManageEngine Endpoint Central campaign, but\n\nit shared several traits with what was described in Fareed’s Securelist write-up. However, this particular VBScript\n\ndidn’t install the ManageEngine RMM. Instead it reached out to f004.backblazeb2[.]com and downloaded a\n\ndropper.\n\nPage 2 of 7\n\nhttps://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\nThe dropper then deployed NSecRTS.exe, which turned out to be another RMM tool called “Ping32” from the\n\nChinese company Shandong Anzai Information Technology, aka NSecsoft. This RMM tool has a history of being\n\nabused as a Remote Access Trojan (RAT) by hackers.\n\nThe Ping32 RMM used HTTP over multiple TCP ports on 143.92.37.168, and it also communicated via UDP port\n\n18987 on the same server.\n\nImage: UDP traffic to 143.92.37.168:18987\n\nPivot to ValleyRAT\n\nI pivoted on the C2 IP 143.92.37.168, which was used by the malicious Ping32 RMM, and got a hit on Triage\n\nSandbox. Triage classified this sample as DonutLoader and V\n\nPage 3 of 7\n\nalleyRAT, and its malware config extractor identified\n\nthe following attributes:\n\nFamily\n\nVersion\n\nC2\n\nCampaign date\n\nThis is interesting, because this is another link between the campaign mentioned in Fareed’\n\nValleyRAT. When I examined the V\n\nCapLoader as well as FlowCarp identified it as Gh0stKCP\n\nsometimes uses to transport its C2 traffic.\n\nhttps://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\nalleyRAT C2 traffic from the Triage sandbox execution I noticed that\n\nvalleyrat_s2\n\n1.0\n\n143.92.37.168:10086\n\n2026-02-02\n\n, which is a UDP-based protocol that V\n\nPage 4 of 7\n\ns blog post and\n\nalleyRAT\n\nhttps://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\nUse this oneliner to upload the PcapNG file from Triage to the free FlowCarp demo server and extract IP:port\n\nIOCs from FlowCarp alerts.\n\nPage 5 of 7\n\nhttps://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\ncurl -fSs --data-binary @260514-agrsxacw6n-behavioral1.pcapng https://demo.flowcarp.com | jq -s -c\n\n'map(select(.event_type==\"alert\")|[(.dest_ip + \":\" + (.dest_port|tostring)), .alert.signature])|unique[]'\n\n[\"143.92.37.168:10086\",\"MALWARE protocol detected: Gh0stKCP\"]\n\nIf you prefer Suricata, use these custom signatures to detect Gh0stKCP:\n\nhttps://github.com/Netresec/Suricata/blob/main/netresec.rules\n\nYou can then use the same jq query as in the FlowCarp example to extract the alert IOCs from Suricata’s eve.json\n\noutput.\n\ncat eve.json | jq -s -c 'map(select(.event_type==\"alert\")|[(.dest_ip + \":\" + (.dest_port|tostring)),\n\n.alert.signature])|unique[]'\n\n[\"143.92.37.168:10086\",\"Gh0stKCP / HP-Socket ARQ handshake\"]\n\n[\"143.92.37.168:10086\",\"Gh0stKCP close\"]\n\nSilver Fox\n\nIt is difficult to attribute the analyzed malware samples to a specific threat actor, but it is possible that they were\n\nused by the notorious Silver Fox group, which is one of China’s largest and most active cybercrime groups.\n\nOn a positive note, China Daily recently reported that Chinese police have taken “criminal compulsory measures”\n\nagainst 27 suspects linked to Silver Fox. The same article also stated that “The gang allegedly sent phishing\n\nemails in bulk, stole corporate data and built fraud scenarios to carry out criminal activities totaling more than 7\n\nmillion yuan ($1 million)”.\n\nLet’s hope this puts a stop to, or at least significantly reduces, the massive flood of malware that has been coming\n\nfrom this threat actor.\n\nIOC List\n\nUnknown Downloader\n\nd43fdaa1f0ee09d7e5f0f94ee9df7b6c (Bitte füllen..vbs)\n\nhxxps://f004.backblazeb2[.]com/file/fadaoxiao/uamcd.pdf\n\nhxxps://f004.backblazeb2[.]com/file/gaosu2/CoreShield.msi\n\nhxxps://fadaoxiao.s3.us-west-004.backblazeb2[.]com/pacc.vbs\n\nac63eb8814f20ffd89ce81f51cba6916 (uamcd.pdf)\n\n9ca134a5ed592a0fb57e2ad910a71c80 (pacc.vbs)\n\nNSecsoft Ping32 RMM C2\n\n143.92.37.168:18987 (UDP)\n\n143.92.37.168:38987 (TCP)\n\n143.92.37.168:48988 (TCP)\n\n143.92.37.168:48991 (TCP)\n\nPage 6 of 7\n\nhttps://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\n143.92.37.168:48992 (TCP)\n\nDonutLoader/ValleyRAT\n\n8266b00c4e45d728cef78b3f5a865f68 (ManagementTool.exe)\n\n143.92.37.168:10086 (UDP)\n\nPosted by Erik Hjelmvik on Thursday, 25 June 2026 09:27:00 (UTC/GMT)\n\nTags: #Gh0stKCP​#ValleyRAT​#Suricata​#FlowCarp​#CapLoader​\n\nSource: https://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT\n\nPage 7 of 7","extraction_quality":1,"language":"EN","sources":["Malpedia"],"origins":["web"],"references":["https://www.netresec.com/?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT"],"report_names":["?page=Blog\u0026month=2026-06\u0026post=Ping32-RMM-and-ValleyRAT"],"threat_actors":[{"id":"8f68387a-aced-4c99-b2a6-aa85071a0ca3","created_at":"2024-06-25T02:00:05.030976Z","updated_at":"2026-09-20T02:00:05.24416Z","deleted_at":null,"main_name":"Void Arachne","aliases":["Silver Fox"],"source_name":"MISPGALAXY:Void Arachne","tools":[],"source_id":"MISPGALAXY","reports":null},{"id":"a7805d1a-b8d0-4a42-ae86-1d8711e0b2b9","created_at":"2024-08-28T02:02:09.729503Z","updated_at":"2026-09-20T02:00:06.625258Z","deleted_at":null,"main_name":"Void Arachne","aliases":["Silver Fox"],"source_name":"ETDA:Void Arachne","tools":["Gh0stBins","Gh0stCringe","HoldingHands RAT","Winos"],"source_id":"ETDA","reports":null}],"ts_created_at":1789437826,"ts_updated_at":1789869680,"ts_creation_date":0,"ts_modification_date":0,"files":{"pdf":"https://archive.orkl.eu/be388fb0179fa9ebe4300fd25a1874ebd04bc0c2.pdf","text":"https://archive.orkl.eu/be388fb0179fa9ebe4300fd25a1874ebd04bc0c2.txt","img":"https://archive.orkl.eu/be388fb0179fa9ebe4300fd25a1874ebd04bc0c2.jpg"}}],"message":"library entries","status":"success"}