
Frozen RAT Builder, Free DNS Alias Keep klovbot Active Since 2017
A cluster of 16 Windows PE32 files tied to the klovbot malware family has been targeting Moldova's technology sector using DarkKomet/XRed RAT builds whose core PE skeleton has gone unmodified for five years. The operator pairs a well-detected file layer with near-invisible network infrastructure: a C2 IP scoring 1 out of 91 detections, routed through free dynamic-DNS and carrying a TLS certificate refreshed as recently as May 29, 2026.
Sixteen Windows PE32 executables tied to the klovbot malware family are circulating against technology-sector targets in Moldova, and the most operationally revealing detail about the campaign is not the payload — it is the degree to which the operator has changed almost nothing since at least 2017. Three of those files carry enough metadata for deep analysis, and what that analysis surfaces is a tradecraft combination that has outlasted most of the defensive signatures written against it: an…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read