logo

Open Directory Exposure Leaks BYOB Framework Across Windows, Linux, and macOS

ID: 1149b4e0-d2b6-5ea0-af94-cda506f11ed6

STIX ID: report--1149b4e0-d2b6-5ea0-af94-cda506f11ed6

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Hunt.io discovered an exposed BYOB command-and-control deployment (primary C2 38.255.43.60) active for ~10 months, distributing obfuscated droppers, stagers and a multi-platform remote access trojan for Windows, Linux, and macOS; two C2 nodes also hosted XMRig for cryptomining. The report details a three-stage infection chain with anti-VM checks, seven persistence mechanisms, extensive post-exploitation modules (keylogging, screenshots, mail harvesting, packet sniffing), multiple web servers and open RDP, and provides IOCs including C2 IPs and service ports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.