Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

BlindEagle

37
Global rank
14 infographic chevron month
Month rank
14 infographic chevron week
Week rank
0
IOCs

BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.

RAT
Type
Unknown
Origin
1 March, 2018
First seen
14 September, 2026
Last seen

How to analyze BlindEagle with ANY.RUN

RAT
Type
Unknown
Origin
1 March, 2018
First seen
14 September, 2026
Last seen

IOCs

IP addresses
20.165.94.63
52.123.224.70
88.221.169.205
150.171.109.100
88.221.169.152
23.216.77.19
48.202.208.48
162.241.60.30
150.171.109.193
128.24.231.65
48.209.138.168
20.190.159.75
2.16.241.201
48.209.133.15
150.171.28.11
2.16.164.66
150.171.109.106
104.18.22.222
172.211.123.248
150.171.27.11
Hashes
3a5078b626e41d20117d260d8b825b039884cfe062c6d462432216d9b07d82b5
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
f9e4da319fe1f5a7d497c452421f4648a24ec7588f309ebea0f0cd61a6251eef
d988156066b7fd22de278fbc96759d2caea6552094ffeb2ddd9307806059c5e4
8b2e057387e9714efef3580a36459acf56aab53c806cd7d7dbb6e17cef977ef9
867a31befa91e9aa232b5edcfa3688230e4d77e4f8f63f782f20017aca9a6343
6540098b19e58aeeda6ee01d0f78ca052e6961efa4a25e514cdd08e6e6631249
ccbb779363f7f2b5174e25ebb1bba5dd9b72c4e08c9f8d64751e95ed3db85571
14bf8af0ec00ec4d1b1c48ed250d95f1917a05b4480866a0f0d3e6575f2fb0ba
04bec01401dc633a4e305486256cb72fb9eaa3accb6e80f26a093aea17ee4c48
7fef29bfb2bed6fbbb02160c53c15e79766d172ec31714e7a31f6fed93674842
34f3d13e671204edd7c8324b40eb7070919c6c67e0e9aaf5d2f8bad5fab09ca7
fbeb1790218a24ac41e8c2e5bfa278508a345cef2e67be7fc2ddd9464ce8a4b2
4e987457f6e0b88119955bff45499d74bc9102631e01e3cad4b9fdcaed4d2f2e
ae0140c26ae95539091f4d4ed9bf99bfe871f02f71d5526d0e156d20b7f18a01
49a6af676b2133a16df0825aa3efa29c4e60d3e0399003ab86ec8a8147273f8a
6ee966926c812be209a7f0db5b7fa51877af46fe02eca2a104b3c498f7a4cb36
Domains
settings-win.data.microsoft.com
www.microsoft.com
go.microsoft.com
fe3cr.delivery.mp.microsoft.com
edge-consumer-static.azureedge.net
crl.microsoft.com
edge.microsoft.com
login.live.com
edge-cloud-resource-static.azureedge.net
edge-mobile-static.azureedge.net
self.events.data.microsoft.com
www.corpomojana.gov.co
google.com
static.edge.microsoftapp.net
api.edgeoffer.microsoft.com
www.fiscalia.gov.co
copilot.microsoft.com
activation-v2.sls.microsoft.com
update.googleapis.com
config.edge.skype.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:qj9cmnh9sykprca2n0mfskm9yrss9_glfve5zbll0fq&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d270%2526e%253d1
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://update.googleapis.com/service/update2/json?cup2key=14:4vln4k3l2anzvfn9wrt9tfll_uhdh0x_a_uyevhu_l4&cup2hreq=6fc52a24f1bd0c39ee26c3d1f4767ab53d9d8598e8bd50002ae757dd693cc741
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://www.corpomojana.gov.co/images/carousel/logofiscalia.png
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
Last Seen at

Recent blog posts

post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 438
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5189
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 10301
comments 0

BlindEagle Malware Exposed: Steganography, Banking Trojans, and 9,000 Victims in One Campaign

Key Takeaways

  • BlindEagle is active and evolving. Operating since at least 2018, the group continuously updates its toolset, adding DLL sideloading, steganography, and new RAT variants.

  • The threat is primarily regional but not exclusively so. Colombia accounts for roughly 87% of known victims, but documented campaigns have reached Ecuador, Chile, Panama, and Spain — and any multinational organization with regional presence is potentially exposed.

  • Phishing is the gateway. Every BlindEagle intrusion begins with a convincing impersonation of a trusted government or financial authority.

  • Commodity RATs, sophisticated impact. Modified open-source RATs equipped with banking credential interception, keylogging, and remote access give the group everything it needs for both espionage and financial fraud.

  • Detection requires behavioral context, not just signatures. The group's use of legitimate platforms (GitHub, Discord, Google Drive) for payload staging, process hollowing for evasion, and DDNS for C2 rotation makes static indicator matching alone insufficient — behavioral detection and up-to-date intelligence are essential.

  • The infection chain is complex but detectable: phishing → geolocation filter → VBScript dropper → steganographic payload → process injection → RAT persistence — leaves multiple detection opportunities for organizations with proper monitoring in place.

  • Proactively defend with ANY.RUN’s Threat Intelligence Feeds for real-time IOC blocking and Threat Intelligence Lookup for rapid investigation of suspicious artifacts — combining both strengthens detection and response against evolving threats like BlindEagle. destinationIP:"181.134.198.53".

IP linked to BlindEagle campaigns Malicious IP linked to BlindEagle campaigns

What is BlindEagle?

BlindEagle is a South American APT group with a dual mandate: intelligence gathering and financial theft. Unlike many nation-state actors that rely on bespoke, sophisticated malware, BlindEagle operates with lean efficiency: adopting and customizing widely available open-source RATs, layering them within multi-stage infection chains, and constantly rotating tools to frustrate defenders.

The group has maintained a years-long targeting pattern — predominantly Colombia, and secondarily Ecuador, Chile, Panama, and Spain — with remarkable consistency. Their phishing emails convincingly impersonate Colombia's tax authority (DIAN), the Attorney General's Office, the Foreign Affairs Ministry, the judicial system, and major financial institutions. Victims receive what looks like an urgent legal notice or government document; one click sets an elaborate infection cascade in motion.

The group's RAT arsenal has included AsyncRAT, RemcosRAT, njRAT, LimeRAT, BitRAT, QuasarRAT, and DCRat, each modified with additional capabilities tailored to the campaign at hand. In espionage operations, these tools capture keystrokes, take screenshots, activate webcams, and exfiltrate files. In financially motivated campaigns, they transform into banking trojans intercepting credentials for Colombian financial institutions in real time.

The group uses geolocation filtering via URL shorteners: anyone accessing a malicious link from outside the targeted country is silently redirected to the legitimate website of whichever government body is being impersonated. This deflects automated threat hunters and frustrates researchers, while keeping infection rates high among intended targets.

ANY.RUN’s Interactive Sandbox allows to safely detonate FlowerStorm samples and analyse full attack chain:

View sandbox analysis

BlindEagle analysis in Interactive Sandbox BlindEagle detonated in Interactive Sandbox

How BlindEagle Threatens Businesses and Organizations

BlindEagle presents serious risks to organizations because it combines stealth, persistence, and operational flexibility.

Key business risks include:

  • Credential theft and account compromise. Stolen credentials may provide attackers with access to VPNs, email environments, cloud platforms, and internal systems.
  • Espionage and sensitive data exposure. Government agencies, financial institutions, and enterprises risk exposure of confidential documents, communications, and strategic data.
  • Operational disruption. Remote access malware enables attackers to manipulate systems, disable defenses, or prepare follow-on attacks.
  • Supply chain and trust exploitation. BlindEagle frequently abuses trusted internal email accounts, making phishing campaigns significantly harder for employees and security tools to identify.
  • Long-term persistence. RAT-based infections allow threat actors to maintain footholds inside networks for extended periods, increasing the risk of lateral movement and secondary payload deployment.
  • Regulatory and compliance exposure. Organizations handling citizen, healthcare, financial, or legal information may face legal consequences after a breach involving sensitive data exfiltration.

For CISOs and SOC teams, BlindEagle is particularly dangerous because its activity often blends into legitimate workflows. The attack chain can look like normal document sharing, judicial notifications, or internal communications until malware execution has already begun.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most at Risk?

Colombia accounts for approximately 87% of observed victims, reflecting the group's core focus. Ecuador, Chile, Panama, and Spain have also been targeted in documented campaigns, indicating the group is willing to expand when the opportunity presents itself. Sectors at heightened risk:

  • Government and public institutions: BlindEagle routinely impersonates and targets judicial bodies, tax agencies, immigration authorities, and peace negotiation bodies. The group specifically targeted Colombia's judicial institutions in campaigns running through early 2025, infecting over 9,000 victims in a single wave.
  • Financial services: Banks, insurance companies, and fintech firms are prime targets. A 2024 campaign focused specifically on Colombia's insurance sector, delivering a customized Quasar RAT designed to steal banking credentials.
  • Energy, oil, and gas: The group has actively targeted this sector since at least 2018, likely for both espionage and operational intelligence.
  • Healthcare and education: Campaigns have swept up hospitals, universities, and health agencies, which tend to have broader attack surfaces and less mature security postures.
  • Law enforcement and immigration: BlindEagle has impersonated and targeted law enforcement and immigration agencies, adding a dimension of intelligence collection around state security activities.

Any organization with employees in Colombia or other targeted Latin American countries including multinational companies with regional offices should consider itself within potential targeting range.

The Evolution of BlindEagle: Key Milestones

2018: Origins

BlindEagle begins operations, primarily targeting Colombian government institutions and financial sector entities. Early campaigns use basic phishing and off-the-shelf RATs, establishing the operational playbook the group will refine over the following years.

2019–2021: Expanding the toolkit

The group cycles through successive RATs — Quasar RAT, AsyncRAT, LimeRAT, BitRAT — demonstrating a pattern of adopting whatever commodity tool best fits the current campaign. Geolocation filtering via URL shorteners becomes a signature defensive tactic.

2022: Remcos and new targets

BlindEagle adds Remcos RAT to its arsenal, deploying it against government entities, private companies, and individuals in Colombia. The group begins experimenting with more elaborate infection chains, including password-protected archives hosted on Google Drive.

Early 2023: Ecuador targeting and sharpened tools

A notable campaign targets Ecuadorian organizations with a refined infection chain, incorporating living-off-the-land techniques (specifically the abuse of mshta) alongside a modified Quasar RAT configured to intercept banking credentials. Fake UUE files and Fsociety-based tooling appear in Colombian campaigns targeting judicial, financial, health, law enforcement, and immigration entities.

Mid-2023

Agent Tesla and expanding surveillance. BlindEagle transitions from njRAT to Agent Tesla as its primary implant in one campaign wave, signaling intent to broaden its surveillance capabilities.

2024: Steganography, DLL sideloading, and the njRAT pivot

BlindEagle begins hiding payloads inside images using steganography, and experiments with DLL sideloading — a technique previously uncharacteristic of the group. Portuguese-language artifacts begin appearing in malicious code, suggesting possible Brazilian involvement or deliberate misdirection. A dedicated campaign targets Colombia's insurance sector using BlotchyQuasar (a customized Quasar RAT variant), initiated via phishing emails impersonating Colombia's tax authority DIAN.

Late 2024–Early 2025

Justice for All campaign. A series of campaigns target Colombian judicial institutions, delivering malicious .url files that exploit behavior similar to CVE-2024-43451 — a Windows NTLMv2 hash disclosure vulnerability. Simply right-clicking, deleting, or dragging the file triggers a WebDAV request that notifies the attacker of the download. The PARAISO campaign alone infects over 1,600 victims with Remcos RAT. Total infections across this campaign wave approach 9,000. GitHub and Bitbucket repositories are abused as distribution platforms for final-stage payloads.

2025: Continued activity and supply chain risk

Darktrace identifies fresh BlindEagle activity targeting customers in Latin America through mid-2025. Researchers link BlindEagle infrastructure to Proton66, a bulletproof hosting provider. The group continues to evolve, with new campaigns targeting Colombian government agencies using DCRat and novel loaders. MITRE ATT&CK formally tracks the group as G0099, cataloguing its growing technique set.

How BlindEagle Gets Into Systems and Spreads

BlindEagle's intrusion methodology is highly consistent across campaigns, making it both predictable in pattern and effective in execution.

Stage 1 — Phishing lure

Everything begins with a carefully crafted phishing email. BlindEagle impersonates trusted institutions: Colombia's tax authority (DIAN), the Attorney General's Office, the judicial system, or major banks. Emails contain urgent language — a tax notice, a court summons, a legal complaint — designed to compel the recipient to act immediately. Attachments may appear to be PDFs or Word documents; links in the email body direct victims to download what appears to be official documentation.

Stage 2 — Geolocation filtering

Before any malicious content is served, a URL shortener checks the victim's geographic location. Connections from outside the targeted country are silently redirected to the legitimate website of the impersonated institution.

Stage 3 — Initial dropper

The victim downloads a compressed archive — ZIP, LHA, or UUE format — containing what appears to be an official document. Inside are Visual Basic Scripts (VBScripts) that, when executed, use WScript, XMLHTTP objects, or PowerShell commands to reach out to attacker-controlled servers or legitimate public platforms (GitHub, Pastebin, Discord, Bitbucket, Google Drive) to download the next-stage payload.

Stage 4 — Intermediate payload

The second-stage artifact may be a text file (with base64 or ASCII-encoded payload), an image file (with the payload concealed via steganography), or a .NET executable masquerading as a legitimate application. The initial dropper decodes and extracts this content, producing an intermediate DLL or .NET injector.

Stage 5 — Process injection and persistence

The injector loads the final RAT payload into the memory of a legitimate Windows process using process hollowing — a technique that causes the malicious code to execute under the guise of a trusted application, evading process-based security tools. The malware then writes itself into the Windows Registry to survive reboots. Command-and-control (C2) communications are established using Dynamic DNS services such as DuckDNS, which allow high IP rotation and rapid subdomain creation, making infrastructure takedown difficult.

Stage 6 — Post-compromise activity

With the RAT running, BlindEagle operators have full remote access: keylogging, screenshot capture, webcam activation, file exfiltration, remote desktop control, and — in financial campaigns — real-time interception of banking credentials as victims navigate to financial websites.

How BlindEagle Functions: Technical Mechanics

RAT rotation and customization

BlindEagle does not develop proprietary malware. Instead, it sources open-source or commodity RATs — AsyncRAT, Remcos, njRAT, LimeRAT, BitRAT, QuasarRAT, DCRat — and customizes them for each campaign. Modifications include adding keylogging routines tuned to specific banking websites, installing secondary plugin frameworks for expanded capability, embedding espionage-focused features such as webcam activation and screen recording, and in at least one documented case, building a complete banking credential interception module into a Quasar RAT variant.

Steganography

BlindEagle has been observed hiding encoded payloads inside image files, using steganographic techniques to conceal malicious code in plain sight. The encoded content is extracted and decoded by the initial dropper before being executed.

Process hollowing

The group's preferred injection method involves hollowing out a legitimate Windows process, replacing its code with the RAT payload.

DLL sideloading

By placing a malicious DLL in a location where a legitimate application will load it, BlindEagle can execute arbitrary code under the cover of a trusted application without triggering standard detection rules.

Living-off-the-land (LotL)

BlindEagle makes extensive use of Windows-native tools and processes — PowerShell, WScript, mshta, the .NET framework — reducing reliance on easily detected third-party malicious executables. Using built-in system tools for malicious purposes blends attacker activity into normal operational noise.

C2 via trusted platforms

By hosting payloads and staging infrastructure on GitHub, Bitbucket, Google Drive, Discord, and Pastebin, BlindEagle benefits from the implicit trust that security tools and network filters extend to these platforms. Blocking them outright would break legitimate business workflows — making BlindEagle's use of them a deliberate and effective defense bypass.

BlindEagle Sample Sandbox Analysis

View this sandbox session to observe BlindEagle full kill chain, payload, connections, and processes.

Blind Eagle (APT-C-36) typically begins its campaigns with a phishing email disguised as a notification from a government agency, court, or financial organization. The email contains a link or attachment that encourages the recipient to download a file and run it:

BlindEagle analysis in Interactive Sandbox BlindEagle detonated in Interactive Sandbox

In more recent campaigns, the group uses malicious Internet Shortcut (.url) files instead of classic .lnk files. Such a file points to a UNC/WebDAV path, for example: \62.60.226[.]200@80\file\WondersharePDFelement.exe

(The name of the executable file often changes, and shortcuts that are literally one day old may already be outdated). The @80 indicates WebDAV over HTTP.

File static analysis in the sandbox File static analysis in the sandbox

After interacting with the file, the system attempts to connect to the remote resource via WebDAV, displaying an interactive dialog window:

File opening confirmation File opening confirmation

If the user confirms, we can see the launch of the specified file in the process details:

Processes linked to the file in the sandbox Processes linked to the file in the sandbox (Note the file path starting with \Device\Mup...) We can also see the WebDAV connection in the scan through the corresponding detection: WebDAV connection detected in the sandbox WebDAV connection detected in the sandbox

After launching the remote payload, behavior may vary, but most often we observe C2 network traffic from the additional payload downloaded from the network. RAT traffic received after launching the payload:

RAT detected in network traffic RAT detected in network traffic

Right away in the sandbox, we can check Network Threats and see detections for Remcos:

Remcos malware detected Remcos malware detected

And the data on connections:

Captured network connections Captured network connections

Additionally, we see that a log file was dropped:

Log file detected in the sandbox Log file detected in the sandbox

As a result, a Remcos RAT was downloaded, which is also visible in the detections:

Remcos RAT detected by the sandbox Remcos RAT detected by the sandbox

Using ANY.RUN sandbox analysis, we can see the entire chain: URL file loading → launching a remote executable file via WebDAV → downloading the malicious payload (BlindEagle most often delivers RATs) → actual operation of the received payload (traffic, dropped files) with detection of the specific malware family.

Besides Interactive Sandbox, ANY.RUN provides threat intelligence solutions that help to protect proactively against BlindEagle and similar threats.

Threat Intelligence Feeds can help businesses:

  • Detect emerging BlindEagle infrastructure;
  • Block malicious IPs, domains, and URLs associated with campaigns;
  • Monitor malware behavior patterns;
  • Correlate network telemetry with fresh indicators;
  • Enrich SIEM, SOAR, EDR, and firewall workflows;
  • Identify infrastructure reuse across campaigns.

Because BlindEagle frequently shifts payloads and hosting providers, real-time IOC enrichment is critical for reducing exposure windows.

Threat Intelligence Lookup helps analysts proactively investigate:

  • Suspicious hashes;
  • PowerShell artifacts;
  • Domains and IPs;
  • File relationships;
  • Behavioral patterns;
  • Similar malware samples linked to BlindEagle operations.

This enables faster threat hunting and incident triage, especially when organizations detect suspicious phishing emails or unusual RAT-like behavior.

Other key measures:

  • Robust email security with sandboxing and attachment scanning.
  • User training on phishing, especially legal/government-themed lures.
  • Endpoint detection and response (EDR) with behavioral monitoring.
  • Least-privilege access, network segmentation, and multi-factor authentication.
  • Regular patching and disabling unnecessary macros/scripts.
  • Monitoring for anomalous PowerShell/WMI usage and WebDAV connections

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

BlindEagle has evolved into a persistent and sophisticated cyber threat actor capable of targeting governments, enterprises, and critical organizations with stealthy phishing campaigns and RAT-based malware.

Its combination of social engineering, PowerShell abuse, DLL sideloading, and evolving malware infrastructure makes it especially dangerous for organizations relying solely on signature-based defenses.

For modern security teams, protection against BlindEagle requires more than endpoint detection alone. It demands continuous threat intelligence, behavioral visibility, rapid IOC correlation, and proactive hunting capabilities capable of identifying campaigns before they escalate into full-scale compromise.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
Adware screenshot
Adware
adware
Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More