
Three-Year-Old njRAT Builder Fingerprint Resurfaces in 2026 Wave
Five .NET executables spanning May 2023 to April 2026 share a single import-table hash and .NET Reactor packing, revealing a njRAT/Bladabindi builder pipeline that hasn't needed to change. The toolkit's only real evolution is its C2 layer, which has grown from one free tunneling service into a five-platform spread of free hosting infrastructure.
Five .NET executables tracked in this reporting cycle, first surfacing as early as May 2023 and as recently as April 2026, share a single import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — and a universal .NET Reactor packing signature, even though VirusTotal's own classifiers split them across three different label aliases: bladabindi, variadic, and cdmip. That split is cosmetic.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read