APTMembers
APT

Six Droppers, One Codebase: The Masquerade Behind FreeEIM and RuntimeBroker

Six Windows binaries branded as a chat utility and a system process turn out to be the same Gh0st RAT-lineage codebase split across five inconsistent vendor labels — farfli, zegost, mulinex, dump, and killmbr. Two samples share an identical import hash, rich header, and 2022 compile timestamp despite VirusTotal recording their first submissions a year apart, showing a re-dropped binary rather than a new build.

Sep 27, 2026, 06:30 (UTC+9)Last seenSep 27, 2026Severity94ByCTX TeamActorSalty SpiderKuKuIOC20MITRE35RegionsUS

A cluster of six Windows binaries surfacing under names like "RuntimeBroker" and "FreeEIM" turns out to be the same Gh0st RAT-lineage codebase wearing five different vendor labels — farfli, zegost, mulinex, dump, and killmbr — a fragmentation that has less to do with new malware and more to do with how detection taxonomy handles a code family that refuses to die.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence