Elektrine lite

โ† Feed

@anyrun_app@infosec.exchange

2026-07-22 14:31 UTC

๐Ÿšจ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ ๐—–๐Ÿฎ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น ๐—–๐—ฎ๐˜‚๐—ด๐—ต๐˜ ๐—ผ๐—ป ๐—ฎ ๐—Ÿ๐—ถ๐˜ƒ๐—ฒ ๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ. Interactive analysis let us capture what static detonation misses โš ๏ธ ๐—ข๐—ฏ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฑ ๐˜๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜๐—ถ๐—ป๐—ด: ๐—š๐—ฒ๐—ฟ๐—บ๐—ฎ๐—ป๐˜† ๐—ฎ๐—ป๐—ฑ ๐—จ๐—ž โ—๏ธ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT โžก๏ธ exo.exe dropper โžก๏ธ Lenovo FnHotkeyUtility.exe โžก๏ธ spkvol.dll sideloading โžก๏ธ Rust loader โžก๏ธ In-memory OVERLORD RAT. ๐Ÿ”ฅ The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory execution, encrypted C2, and active data exfiltration. 1๏ธโƒฃ we.exe connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands hidden in HTML comments and a spoofed porsche[.]com Host header. 2๏ธโƒฃ exo.exe unpacks to C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo binary, sideloads spkvol.dll, and delivers a fileless overlord-client Go agent. ๐Ÿ“Œ OVERLORD connects to lord[.]kirkdridebridge[.]com:5173 over mTLS-encrypted C2. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration. Observed capabilities include remote access, HVNC, keylogging, audio recording, SOCKS proxying, file management, browser/messenger/wallet data theft, and Solana drainer activity. ๐Ÿ‘จโ€๐Ÿ’ป See the full execution chain and collect #IOCs: https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoservice&utm_term=220726 โšก๏ธ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoenterpriselanding&utm_term=220726 #cybersecurity #infosec

Replies (1)

  • @anyrun_app@infosec.exchange 2026-07-22 14:32

    ๐ŸŽฏ IOCs and behavioral patterns: Python RAT (Stage 1): C2: live.rnsn[.]live โ†’ 69.169.111[.]81, TCP 8585 HTTP request markers: GET /International, X-Secret: 12345, Host: www.porsche[.]com, Referer: /|1.1.3 HTTP response decoy markers: Fullscreen Spinner + commands encoded in comment strings OVERLORD RAT (Stage 2): C2: lord.kirkdridebridge[.]com โ†’ 163.245.218[.]93, TCP 5173, mTLSv1.3 channel encryption Host artifacts: C:\Users\Public\Windows\win32\we.exe โ€ฆ\run.vbs โ€ฆ\win6\exo.exe .cmd C:\ProgramData\sysid.txt (we.exe bot UUID) C:\ProgramData\DeepSkyBlueIndianRed\* โ†’ FnHotkeyUtility.exe, spkvol.dll, ludp.dll, msvcp140.dll, vcruntime140*.dll dropped executables Registry: HKCU...\Run: SkypeUpd=โ€ฆ\win32\we.exe HKCU...\Run: Winrarservice=โ€ฆ\win32\run.vbs Mutexes: Global\Overlord-1_oVC9y33fSmT7DVUv0HJn9Y (ForestGreenLightSlateGray object) Inno Setup cmdline password: f1846950-ca2f-4f9b-bd08-4807e431faa9 SHA256: 38cec7299bcbcc334633c87de5ed0d8355df8c73fadd26a8b5ca3862c2ea4357 (we.exe) 6805a1cb9b26b629f94aa3cf062e78eb4a5d259f459c0d8ca5a43cc08b16154b (client1.1.3.pyc) 7f53b7a21ba1418f56afac2f5f9db18bcca48d0c9ab7c3bee15a01db57d5fe5c (exo.exe) 9ab2f85ab539cea0f868c0b2a5219c3a8ccfef5365d74cc2cd455cb06d243f65 (upd.exe) 31c97b6e93112cae7bfce17d5979ccd513111b74165fc6ef471a9f8c821ae879 (spkvol.dll) ๐Ÿ“ MITRE ATT&CK: T1059 โ€” Command and Scripting Interpreter T1105 โ€” Ingress Tool Transfer T1547.001 โ€” Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1027 โ€” Obfuscated Files or Information T1574.002 โ€” Hijack Execution Flow: DLL Side-Loading T1113 โ€” Screen Capture T1123 โ€” Audio Capture T1056.001 โ€” Input Capture: Keylogging T1041 โ€” Exfiltration Over C2 Channel

    Open ##4014282