
Nine-File Toolchain With Zero PE Imports Targets Six Countries via Dedicated AS
A campaign tracked since late May 2026 deploys six malware families — including WoodyRAT, BazarLoader, and a dedicated EDR-bypass binary — all processed through a shared packer that strips every PE import table. All three C2 addresses resolve to a single autonomous system, AS214351, that has been quietly expanding its address space since October 2024.
Nine Windows executables, zero PE imports between them, and a dedicated binary whose sole purpose is to kill endpoint defenses before the rest of the payload stack arrives — this is the operational profile of a campaign CTX Team has been tracking since late May 2026, one that pairs an unusually complete evasion architecture with a purpose-built autonomous system that its operator has been quietly expanding for the better part of a year.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read