Careful of the RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft
RemotePanel and BoundSiphon are two .NET malware components delivered together via malicious NuGet packages impersonating Chinese UI libraries. RemotePanel is a persistent remote access tool masquerading as the Windows Time service, providing extensive control over infected systems. BoundSiphon is an in-memory stealer targeting browser credentials, cryptocurrency wallets, password managers, and sensitive documents. The malware uses a blockchain-based mechanism to dynamically resolve its command and control servers, enabling infrastructure rotation without redeployment. The campaign involves typosquatting private or internal Chinese .NET libraries, affecting developer workstations and CI/CD environments. The malware ecosystem is modular, separating persistence from data theft, allowing operators to maintain capabilities while swapping components. Tens of thousands of downloads have been recorded, and the packages remain available on NuGet at the time of reporting. Blackpoint Cyber has detections for key behaviors in the infection chain, aiding defense despite evolving payloads and infrastructure.
AI Analysis
Technical Summary
Blackpoint Cyber's Adversary Pursuit Group identified two .NET malware components, RemotePanel and BoundSiphon, delivered via five malicious NuGet packages impersonating Chinese .NET UI and infrastructure libraries. RemotePanel establishes persistence by masquerading as the Windows Time service and offers operators broad system control, including PowerShell, file/process management, screen access, modular HVNC, and fleet management. It uses a BNB Smart Chain contract to resolve its active C2 server, enabling infrastructure rotation without redeployment. BoundSiphon operates primarily in memory, stealing browser credentials, cryptocurrency wallets, password manager data, and protected documents. The malicious packages use .NET Reactor protection and JIT hooking to evade detection and execute payloads. The campaign targets developer workstations and CI/CD build servers, with approximately 65,000 downloads. The operator uses version rotation and unlisting to evade detection. The modular malware ecosystem allows operators to replace components while maintaining persistent access and data theft capabilities. Blackpoint Cyber has detections for key behaviors across the infection chain.
Potential Impact
Successful infection results in persistent remote access to affected systems and theft of sensitive data including browser credentials, cryptocurrency wallets, password manager data, and protected documents. This increases the risk of account takeover, fraud, and ongoing compromise of developer workstations and CI/CD infrastructure. The malware's use of blockchain-based C2 resolution and modular design complicates detection and remediation efforts.
Mitigation Recommendations
Blackpoint Cyber has detections in place for key behaviors across the infection chain, providing coverage despite evolving payloads and infrastructure. Users should remove the identified malicious NuGet packages and avoid installing packages from untrusted or suspicious sources, especially those impersonating Chinese .NET libraries. Monitor for unusual persistence mechanisms masquerading as legitimate services such as the Windows Time service. Follow vendor advisories and NuGet Gallery takedown notices for updates on package availability and remediation. Patch status is not yet confirmed — check the NuGet Gallery and vendor advisories for current remediation guidance.
Careful of the RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft
Description
RemotePanel and BoundSiphon are two .NET malware components delivered together via malicious NuGet packages impersonating Chinese UI libraries. RemotePanel is a persistent remote access tool masquerading as the Windows Time service, providing extensive control over infected systems. BoundSiphon is an in-memory stealer targeting browser credentials, cryptocurrency wallets, password managers, and sensitive documents. The malware uses a blockchain-based mechanism to dynamically resolve its command and control servers, enabling infrastructure rotation without redeployment. The campaign involves typosquatting private or internal Chinese .NET libraries, affecting developer workstations and CI/CD environments. The malware ecosystem is modular, separating persistence from data theft, allowing operators to maintain capabilities while swapping components. Tens of thousands of downloads have been recorded, and the packages remain available on NuGet at the time of reporting. Blackpoint Cyber has detections for key behaviors in the infection chain, aiding defense despite evolving payloads and infrastructure.
Reddit Discussion
Tl:dr
- Blackpoint’s Adversary Pursuit Group (APG) identified two previously undocumented .NET malware components delivered together through a ClickFix chain: RemotePanel, a persistent remote access platform, and BoundSiphon, a credential and cryptocurrency stealer.
- RemotePanel establishes persistence by masquerading as the Windows Time service and gives operators broad control over infected systems, including PowerShell, file and process management, screen access, modular HVNC, and fleet management.
- RemotePanel uses a BNB Smart Chain contract to resolve its active Command and Control (C2) server, allowing operators to rotate infrastructure without rebuilding or redeploying the RAT.
- BoundSiphon runs primarily from memory and targets browser credentials and sessions, cryptocurrency wallets, password manager data, and selected documents, including secrets protected by Chromium App-Bound Encryption.
- APG identified strong code and build overlap between BoundSiphon and a stealer previously documented by Socket, linking the sample to an earlier stealer codebase or builder lineage.
- APG is seeking additional research and samples tied to RemotePanel, BoundSiphon, the AntiSNG implementation, Socket linked stealer activity, and the BNB Smart Chain resolver to help connect the remaining lineage and infrastructure gaps.
- RemotePanel and BoundSiphon reflect a broader shift toward modular malware ecosystems that separate persistent access from data theft, allowing operators to replace infrastructure and individual components while retaining the underlying capabilities needed to continue an operation.
- For victims, a single successful infection can lead to persistent remote access and theft of credentials, browser sessions, cryptocurrency wallets, password manager data, and other sensitive information, increasing the risk of account takeover, fraud, and continued compromise.
- Blackpoint has detections in place for key behaviors across the infection chain, providing coverage even as individual payloads and infrastructure change.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Blackpoint Cyber's Adversary Pursuit Group identified two .NET malware components, RemotePanel and BoundSiphon, delivered via five malicious NuGet packages impersonating Chinese .NET UI and infrastructure libraries. RemotePanel establishes persistence by masquerading as the Windows Time service and offers operators broad system control, including PowerShell, file/process management, screen access, modular HVNC, and fleet management. It uses a BNB Smart Chain contract to resolve its active C2 server, enabling infrastructure rotation without redeployment. BoundSiphon operates primarily in memory, stealing browser credentials, cryptocurrency wallets, password manager data, and protected documents. The malicious packages use .NET Reactor protection and JIT hooking to evade detection and execute payloads. The campaign targets developer workstations and CI/CD build servers, with approximately 65,000 downloads. The operator uses version rotation and unlisting to evade detection. The modular malware ecosystem allows operators to replace components while maintaining persistent access and data theft capabilities. Blackpoint Cyber has detections for key behaviors across the infection chain.
Potential Impact
Successful infection results in persistent remote access to affected systems and theft of sensitive data including browser credentials, cryptocurrency wallets, password manager data, and protected documents. This increases the risk of account takeover, fraud, and ongoing compromise of developer workstations and CI/CD infrastructure. The malware's use of blockchain-based C2 resolution and modular design complicates detection and remediation efforts.
Defensive Guidance
Blackpoint Cyber has detections in place for key behaviors across the infection chain, providing coverage despite evolving payloads and infrastructure. Users should remove the identified malicious NuGet packages and avoid installing packages from untrusted or suspicious sources, especially those impersonating Chinese .NET libraries. Monitor for unusual persistence mechanisms masquerading as legitimate services such as the Windows Time service. Follow vendor advisories and NuGet Gallery takedown notices for updates on package availability and remediation. Patch status is not yet confirmed — check the NuGet Gallery and vendor advisories for current remediation guidance.
Technical Details
- Source Type
- Subreddit
- Malware
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":32,"reasons":["external_link","established_author"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ab7fefef7a7c5410687cb25
Added to database: 09/26/2026, 17:21:02 UTC
Last enriched: 09/26/2026, 17:21:15 UTC
Last updated: 09/27/2026, 03:17:43 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.