logo

Exposed BYOB C2 Infrastructure Reveals a Multi-Stage Malware Deployment

ID: a5a206c5-b108-5023-bfea-ff99f7d30cbe

STIX ID: report--a5a206c5-b108-5023-bfea-ff99f7d30cbe

Feed Name: Hunt.io Blog

Threat Score
78/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report documents discovery of an exposed command-and-control open directory hosting a complete BYOB RAT deployment (dropper, stager, payload) that targets Windows, Linux and macOS. The multi-stage Python malware implements multiple persistence mechanisms, encrypted HTTP C2, and post-exploitation features including keylogging, packet capture, and Outlook email harvesting; infrastructure pivots uncovered five C2 nodes (two also running XMRig miners) and a set of actionable IOCs and mitigation/detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.