FILEMembers
FILE

One .NET Builder, Two Malware Families, One Turkish C2 IP

A shared PE import-table hash ties an AgentTesla infostealer and an XWorm RAT to a single .NET build pipeline. Both PEiD-packed assemblies route C2 traffic through a Turkish cloud IP whose RIPE block was registered just 26 days before the April 2026 payload wave. The campaign targets hospitality and technology organisations in Morocco and Turkey.

May 29, 2026, 06:45 (UTC+9)Last seenMay 29, 2026Severity94ByCTX TeamIOC23MITRE41RegionsMATR

A single PE import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the forensic thread that ties together what initially appears to be two separate commodity malware campaigns. On one end sits a 239-kilobyte AgentTesla infostealer, first submitted to VirusTotal in December 2025 and confirmed malicious by all three sandboxes that analysed it.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence