C&CMembers
C&C

Nine-File Toolchain With Zero PE Imports Targets Six Countries via Dedicated AS

A campaign tracked since late May 2026 deploys six malware families — including WoodyRAT, BazarLoader, and a dedicated EDR-bypass binary — all processed through a shared packer that strips every PE import table. All three C2 addresses resolve to a single autonomous system, AS214351, that has been quietly expanding its address space since October 2024.

Jun 22, 2026, 17:26 (UTC+9)Last seenJun 22, 2026Severity100ByCTX TeamIOC40MITRE66RegionsDZESIDITRO

Nine Windows executables, zero PE imports between them, and a dedicated binary whose sole purpose is to kill endpoint defenses before the rest of the payload stack arrives — this is the operational profile of a campaign CTX Team has been tracking since late May 2026, one that pairs an unusually complete evasion architecture with a purpose-built autonomous system that its operator has been quietly expanding for the better part of a year.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence