
Six Droppers, One Codebase: The Masquerade Behind FreeEIM and RuntimeBroker
Six Windows binaries branded as a chat utility and a system process turn out to be the same Gh0st RAT-lineage codebase split across five inconsistent vendor labels — farfli, zegost, mulinex, dump, and killmbr. Two samples share an identical import hash, rich header, and 2022 compile timestamp despite VirusTotal recording their first submissions a year apart, showing a re-dropped binary rather than a new build.
A cluster of six Windows binaries surfacing under names like "RuntimeBroker" and "FreeEIM" turns out to be the same Gh0st RAT-lineage codebase wearing five different vendor labels — farfli, zegost, mulinex, dump, and killmbr — a fragmentation that has less to do with new malware and more to do with how detection taxonomy handles a code family that refuses to die.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read