FILEMembers
FILE

Frozen RAT Builder, Free DNS Alias Keep klovbot Active Since 2017

A cluster of 16 Windows PE32 files tied to the klovbot malware family has been targeting Moldova's technology sector using DarkKomet/XRed RAT builds whose core PE skeleton has gone unmodified for five years. The operator pairs a well-detected file layer with near-invisible network infrastructure: a C2 IP scoring 1 out of 91 detections, routed through free dynamic-DNS and carrying a TLS certificate refreshed as recently as May 29, 2026.

May 30, 2026, 01:34 (UTC+9)Last seenMay 30, 2026Severity75ByCTX TeamIOC17MITRE24RegionsMD

Sixteen Windows PE32 executables tied to the klovbot malware family are circulating against technology-sector targets in Moldova, and the most operationally revealing detail about the campaign is not the payload — it is the degree to which the operator has changed almost nothing since at least 2017. Three of those files carry enough metadata for deep analysis, and what that analysis surfaces is a tradecraft combination that has outlasted most of the defensive signatures written against it: an…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence