216.73.216.6

Exposed BYOB C2 Infrastructure Reveals a Multi-Stage Malware Deployment

· Published 29/01/2026 12:49 · Modified 29/01/2026 16:48

Export JSON

Essential information

Published
29/01/2026 12:49
Modified
29/01/2026 16:48
Tags
2026-01-29 byob cross-platform cryptomining infrastructure reuse keylogging multi-stage packet-capture persistence post-exploitation xmrig
Related entities
4 observables, 2 malware, 3 others

Description

An exposed open directory on a command and control server revealed a complete deployment of the (Build Your Own Botnet) framework. The infection chain targets Windows, Linux, and macOS platforms, implementing seven mechanisms. The malware includes extensive capabilities such as , packet capture, and email harvesting. Analysis uncovered a modular design with encrypted C2 communications and across multiple regions. Two nodes also hosted cryptocurrency miners, indicating additional monetization efforts. The campaign has been operational for approximately 10 months, demonstrating geographic and provider diversification in its infrastructure.

External references