FILEMembers
FILE

RuntimeBroker Impersonator Rides a Frozen C2 Backbone

A freshly repacked dropper disguised as runtimebroker.exe and internally named WmiPrvSE carries a full anti-analysis stack, but the three IPs behind it all sit on the same Femo IT Solutions ASN CTX Team has tracked before. The payload churns while the hosting infrastructure underneath stays completely static.

Aug 31, 2026, 23:10 (UTC+9)Last seenAug 31, 2026Severity100ByCTX TeamActorWizard SpiderGrim SpiderIOC10MITRE34RegionsCHJO

A dropper carrying the internal name WmiPrvSE and exported to disk as runtimebroker.exe has surfaced with a full anti-analysis stack — debugger checks, deliberate execution stalling, and a Zenbox sandbox verdict of MALWARE/EVADER at 88% confidence — while the infrastructure behind it has not moved at all. The three IP addresses tied to this activity sit on the same autonomous system, AS214351, registered to Femo IT Solutions Limited, that CTX Team has already tracked in earlier coverage of this…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence