logo

Exposed Open Directory Leaks BYOB Framework Across Windows, Linux, and macOS

ID: 2c94ff07-ad7d-5c59-b19c-2064d8fa0725

STIX ID: report--2c94ff07-ad7d-5c59-b19c-2064d8fa0725

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

## Executive summary Threat researchers found an exposed open directory on a command-and-control server (38.255.43.60:8081) hosting a full deployment of the BYOB framework — a multi-stage, cross‑platform Remote Access Trojan capable of persistent access on Windows, Linux, and macOS. The report describes a 3-stage infection chain (obfuscated dropper, VM-aware stager, 123 KB RAT) with multiple persistence mechanisms, modular surveillance tools (keylogger, packet sniffer, Outlook harvesting), evidence of cryptojacking co-hosted on C2 nodes, and indicators of active infrastructure operational since at least March 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.