C&CMembers
C&C

Sandbox-Aware Data Collector Beacons Through Rented VPN Relay Network

A tiny JavaScript 'datacollector' sample deliberately stalls before running to dodge automated sandboxes, then beacons out to a rotating pool of commercial VPN and VPS addresses spanning at least eight autonomous systems on four continents. No actor or malware family is attributed — the notable element is the infrastructure discipline behind an otherwise unremarkable script.

Aug 14, 2026, 22:29 (UTC+9)Last seenAug 14, 2026Severity100ByCTX TeamIOC39MITRE11

A 2.6-kilobyte JavaScript file quietly filed as executors/200.js — self-identified in threat classification as a "datacollector" (eb9e1d58c0…) — has been observed deliberately stalling before it runs, a behaviour flagged in its own analysis tags as staying dormant "instead of acting immediately." Once it does wake up, it beacons out to a rotating pool of IP addresses that reads less like a fixed command post and more like a rental fleet: ten of fourteen IPs tied to this activity carry an…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence