FILEMembers
FILE

Ten-Year-Old ranapama Injector Still Harvesting US Retail Credentials in 2026

A Win32 injector compiled in June 2015 remains an active credential-theft tool against US retail targets in 2026, combining process hollowing, multi-layer sandbox evasion, and simultaneous browser, file, and registry harvesting. Its C2 traffic routes through a purpose-provisioned LeaseWeb Netherlands node backed by a 51-IP relay pool spanning Eastern Europe, the Caucasus, and beyond. Eighteen of 56 antivirus engines still fail to detect it.

Jun 27, 2026, 09:45 (UTC+9)Last seenJun 27, 2026Severity100ByCTX TeamIOC60MITRE30RegionsUS

A Win32 injector compiled in June 2015 and first submitted to public malware repositories that same month is running active credential-theft operations against US retail targets in 2026 — not as a curiosity or a legacy artifact, but as a functional, evasion-engineered payload routing traffic through a 51-node relay pool spanning at least ten autonomous systems across Eastern Europe, the Caucasus, and Western Europe.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence