C&CMembers
C&C

Three-Year-Old njRAT Builder Fingerprint Resurfaces in 2026 Wave

Five .NET executables spanning May 2023 to April 2026 share a single import-table hash and .NET Reactor packing, revealing a njRAT/Bladabindi builder pipeline that hasn't needed to change. The toolkit's only real evolution is its C2 layer, which has grown from one free tunneling service into a five-platform spread of free hosting infrastructure.

Aug 31, 2026, 15:07 (UTC+9)Last seenAug 31, 2026Severity100ByCTX TeamActorLazarus GroupHastati GroupIOC18MITRE33RegionsUS

Five .NET executables tracked in this reporting cycle, first surfacing as early as May 2023 and as recently as April 2026, share a single import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — and a universal .NET Reactor packing signature, even though VirusTotal's own classifiers split them across three different label aliases: bladabindi, variadic, and cdmip. That split is cosmetic.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence