
PayPal Lure Fronts Three-Family Malware Stack Tied to FortiGate C2
A trojanised PayPal credential-checker delivers a layered payload chain — ConfuserEx-packed droppers, reflective loaders, and a worm — all beaconing to a single Russian IP presenting an anomalous FortiGate device certificate. CTX Team has tracked the operation from October 2024 through confirmed C2 contact in June 2026, with the same ConfuserEx packing discipline applied uniformly across three distinct malware families.
A trojanised credential-checker masquerading as a PayPal email validation tool has been serving as the entry point for a multi-stage payload operation that deploys at least three functionally distinct malware families — all wrapped in the same ConfuserEx Mod obfuscation layer — before routing command-and-control traffic to a single Russian IP address that presents a FortiGate appliance certificate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read