FILEMembers
FILE

Decade-Old njRAT Stub Pair Resurfaces as 'Black Atlas' Campaign

Two unsigned njRAT stub binaries sharing an identical imphash and 2014 compile timestamp are anchoring a threat-feed cluster labeled 'Operation Black Atlas,' first surfaced in 2026. A single No-IP dynamic-DNS hostname is the only network indicator, and three of five catalogued file hashes carry no metadata at all.

Jun 30, 2026, 10:01 (UTC+9)Last seenJul 29, 2026Severity86ByCTX TeamActorOperation Black AtlasIOC6MITRE33RegionsUS

Two unsigned Windows executables sharing an identical import-table hash and an identical compile timestamp are the spine of a njRAT cluster that a threat feed has only just begun surfacing under the label "Operation Black Atlas" — despite the underlying files dating to October 2014. The binaries, catalogued as c81b26e4b7cc5d3b3ab7aedb9da06b6b1cf863a2d475ac12f590b5b2a18e515a (internally named Stub.exe, 96KB) and b85913770053b4ac5ba69766924f6aab10e1ccc346bfb09571debdbd1bf37727 (internally named…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence