
Six-Year-Old Phorpiex Dropper Hits Kazakhstan on Fresh Romanian VPS
A 2019 Windows executable masquerading as a tape-toolbar utility is actively beaconing to a Romanian VPS provisioned in February 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan. The dropper combines Phorpiex botnet functions, a USB worm, and a ClipBanker cryptocurrency address hijacker behind a layered evasion stack that defeated one of two sandbox environments at 99% confidence.
A 412-kilobyte Windows executable — unsigned, packed, and masquerading as a tape-toolbar utility from the year 2000 — has been actively beaconing to a freshly provisioned Romanian virtual private server since at least March 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read