FILEMembers
FILE

Single Obfuscation Builder Links BAT Stager and MSIL Dropper in 19-Country Campaign

An 8 KB batch stager and an 85 KB .NET dropper share a UTF-16 plus Base64 PowerShell encoding fingerprint, confirming both were produced by the same builder toolkit. The dropper impersonates a Bitvise SSH Client installer and retrieves its payload from a Cloudflare-proxied domain via a URL disguised as a JPEG fetch. CTX Team has assigned the campaign severity 77 across targets in 19 countries spanning technology, telecom, and education verticals.

Jun 25, 2026, 22:43 (UTC+9)Last seenJun 25, 2026Severity77ByCTX TeamIOC12MITRE30RegionsATBDCACHCY

An 8-kilobyte DOS batch file and an 85-kilobyte .NET executable — separated by file type, detection rate, and apparent purpose — turn out to share a single obfuscation fingerprint that binds them into a deliberately engineered attack chain. The YARA rule SUSP_PS1_JAB_Pattern_Jun22_1, authored by Florian Roth of Nextron Systems and drawn from the Neo23x0 signature-base, co-fires on both components: the batch stager (SHA-256 02af6b5d…) and the MSIL dropper (SHA-256 d35dbfec…).

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence