C&CMembers
C&C

Six-Year-Old Phorpiex Dropper Hits Kazakhstan on Fresh Romanian VPS

A 2019 Windows executable masquerading as a tape-toolbar utility is actively beaconing to a Romanian VPS provisioned in February 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan. The dropper combines Phorpiex botnet functions, a USB worm, and a ClipBanker cryptocurrency address hijacker behind a layered evasion stack that defeated one of two sandbox environments at 99% confidence.

May 29, 2026, 20:56 (UTC+9)Last seenJun 12, 2026Severity100ByCTX TeamIOC19MITRE36RegionsKZ

A 412-kilobyte Windows executable — unsigned, packed, and masquerading as a tape-toolbar utility from the year 2000 — has been actively beaconing to a freshly provisioned Romanian virtual private server since at least March 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence