
MSIL/Bobik Dropper Stays Live as Mystery Second File Hints at New Payload
A packed .NET dropper deploying an XMRig miner and PureLog credential stealer across 42 countries remains active as of 23 June 2026, with its Contabo-hosted C2 infrastructure unchanged. A second file SHA256 has entered the indicator set carrying zero metadata, suggesting the operator may be staging a new payload variant the security community has not yet characterised.
A 982-kilobyte unsigned .NET assembly — its PE timestamp deliberately forged to the year 2085 to confound timeline-based triage, its primary code section packed to an entropy of 7.64 — has been confirmed active as recently as 23 June 2026, deploying an XMRig-compatible cryptocurrency miner and PureLog credential stealer simultaneously to compromised endpoints across six industry verticals and 42 countries.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read