INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
One Build Path Links Infostealer, RAT, and Ransomware Family
| 2026-09-01 22:50 HIGH MEDIUM RANSOMWARE & EXTORTION DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A recent compilation artifact has revealed a sophisticated cyber operation linking an infostealer, a remote-access tool, and a ransomware family to a single developer. The Rust-based infostealer named Zer0day Stealer exfiltrates cryptocurrency wallets, browser credentials, Office documents, and VPN configurations, while the HVNC remote-control tool enables hidden remote desktop sessions with evasion techniques such as AMSI and ETW evasion. This operation spans Windows, Linux, and macOS platforms, utilizing multiple droppers written in C, Rust, and PowerShell to deliver malicious payloads. The ransomware family linked to this developer is ENIGMA Locker, which further highlights the scope of this threat. Notably, a botnet component was discovered, indicating an organized cybercrime operation. This incident serves as a critical reminder of the importance of monitoring compilation artifacts for potential threats, and its discovery has significant implications for threat mapping and attribution efforts.
Technical Mitigations AI-generated
• Implement AMSI (Advanced Threat Protection) and ETW (Event Tracing for Windows) evasion techniques to prevent HVNC remote-control tool from functioning.
• Regularly review build timestamps and compilation artifacts to identify potential malware operations and enable comprehensive attribution and threat mapping.
• Utilize secure coding practices, such as code reviews and static analysis tools, to detect and prevent Rust-based infostealer (Zer0day Stealer) exfiltration of sensitive data.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
12463a••••••••••••••••••••••••••••••••••
d0f073••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
6aef80••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
f9964a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
7cb59a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
d22254••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
cryptocurrencycryptocurrency
Incident Timeline
2026/09/01
A single leftover build path links an infostealer, a remote-access tool (HVNC), and a ransomware family to a developer's home directory.
Click on any entity below to view its context and source!
organisation
Stealer
A compilation artifact, specifically a developer's home directory path (/home/tcherber/.cargo/), linked multiple malware families including a Rust-based infostealer named Zer0day Stealer, an HVNC remote-control tool, and ENIGMA Locker ransomware to a single developer.
organisation
HVNC
A compilation artifact, specifically a developer's home directory path (/home/tcherber/.cargo/), linked multiple malware families including a Rust-based infostealer named Zer0day Stealer, an HVNC remote-control tool, and ENIGMA Locker ransomware to a single developer.
organisation
FUD
Build timestamps indicated development occurred within weeks, and infrastructure leaked evidence of additional tools including FUD-Crypter, Botnet, and C2 Agent components, demonstrating how overlooked compilation artifacts enable comprehensive attribution and threat mapping.
infrastructure
Windows
Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS.
infrastructure
Linux
Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS.
infrastructure
Macos
Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS.
organisation
Office
The infostealer exfiltrates cryptocurrency wallets, browser credentials, Office documents, and VPN configurations.
organisation
AMSI
The HVNC tool enables hidden remote desktop sessions and implements AMSI and ETW evasion techniques.
organisation
ETW
The HVNC tool enables hidden remote desktop sessions and implements AMSI and ETW evasion techniques.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS.
Metrics
infrastructure
Linux
Affected Product
Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS.
Metrics
infrastructure
Macos
Affected Product
Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS.
Intelligence Sources
AlienVault OTX
2026-09-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:25
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
organisation
Identified Entity
Stealer
entity
3x
infrastructure
Affected Product
Windows
software
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
tactic
MITRE ATT&CK Technique
T1584.005 - Botnet
technique
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.