C&CMembers
C&C

A Miner Wearing the Face of a Visual C++ Runtime

A packed .NET coinminer disguised as msvcp110.exe has replaced dropper payloads in a campaign CTX Team has tracked since April. The new binary communicates with a persistent single-node C2 on Contabo, marking a pivot from delivery-stage malware to direct resource hijacking.

Jul 1, 2026, 06:15 (UTC+9)Last seenJul 1, 2026Severity100ByCTX TeamIOC6MITRE36RegionsIQKRTR

##A Miner Wearing the Face of a Visual C++ Runtime A packed .NET coinminer masquerading as the Microsoft Visual C++ runtime file msvcp110.exe has replaced the dropper payloads in a campaign CTX Team has been tracking since April, marking a clear pivot from delivery-stage malware to direct resource hijacking. The new primary binary — a 774 KB PE32+ assembly first submitted on 2026-04-17 — deploys into C:\Users\[user]\AppData\Roaming\msvcp110_win\msvcp110.exe, a user-writable path whose filename…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence