Open Directory Exposure Leaks BYOB Framework Across Windows, Linux, and macOS
ID: 1149b4e0-d2b6-5ea0-af94-cda506f11ed6
STIX ID: report--1149b4e0-d2b6-5ea0-af94-cda506f11ed6
Feed Name: GBHackers
Hunt.io discovered an exposed BYOB command-and-control deployment (primary C2 38.255.43.60) active for ~10 months, distributing obfuscated droppers, stagers and a multi-platform remote access trojan for Windows, Linux, and macOS; two C2 nodes also hosted XMRig for cryptomining. The report details a three-stage infection chain with anti-VM checks, seven persistence mechanisms, extensive post-exploitation modules (keylogging, screenshots, mail harvesting, packet sniffing), multiple web servers and open RDP, and provides IOCs including C2 IPs and service ports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
