FILEMembers
FILE

PayPal Lure Fronts Three-Family Malware Stack Tied to FortiGate C2

A trojanised PayPal credential-checker delivers a layered payload chain — ConfuserEx-packed droppers, reflective loaders, and a worm — all beaconing to a single Russian IP presenting an anomalous FortiGate device certificate. CTX Team has tracked the operation from October 2024 through confirmed C2 contact in June 2026, with the same ConfuserEx packing discipline applied uniformly across three distinct malware families.

Jun 8, 2026, 19:41 (UTC+9)Last seenJun 15, 2026Severity100ByCTX TeamIOC16MITRE36RegionsRO

A trojanised credential-checker masquerading as a PayPal email validation tool has been serving as the entry point for a multi-stage payload operation that deploys at least three functionally distinct malware families — all wrapped in the same ConfuserEx Mod obfuscation layer — before routing command-and-control traffic to a single Russian IP address that presents a FortiGate appliance certificate.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence