Exposed Open Directory Leaks BYOB Framework Across Windows, Linux, and macOS
ID: 2c94ff07-ad7d-5c59-b19c-2064d8fa0725
STIX ID: report--2c94ff07-ad7d-5c59-b19c-2064d8fa0725
Feed Name: cybersecurityNews.com
## Executive summary Threat researchers found an exposed open directory on a command-and-control server (38.255.43.60:8081) hosting a full deployment of the BYOB framework — a multi-stage, cross‑platform Remote Access Trojan capable of persistent access on Windows, Linux, and macOS. The report describes a 3-stage infection chain (obfuscated dropper, VM-aware stager, 123 KB RAT) with multiple persistence mechanisms, modular surveillance tools (keylogger, packet sniffer, Outlook harvesting), evidence of cryptojacking co-hosted on C2 nodes, and indicators of active infrastructure operational since at least March 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
