Skip to main content

Careful of the RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft

0
Medium
Published: 09/24/2026 (09/24/2026, 17:58:52 UTC)
Source: Reddit Malware

Description

RemotePanel and BoundSiphon are two .NET malware components delivered together via malicious NuGet packages impersonating Chinese UI libraries. RemotePanel is a persistent remote access tool masquerading as the Windows Time service, providing extensive control over infected systems. BoundSiphon is an in-memory stealer targeting browser credentials, cryptocurrency wallets, password managers, and sensitive documents. The malware uses a blockchain-based mechanism to dynamically resolve its command and control servers, enabling infrastructure rotation without redeployment. The campaign involves typosquatting private or internal Chinese .NET libraries, affecting developer workstations and CI/CD environments. The malware ecosystem is modular, separating persistence from data theft, allowing operators to maintain capabilities while swapping components. Tens of thousands of downloads have been recorded, and the packages remain available on NuGet at the time of reporting. Blackpoint Cyber has detections for key behaviors in the infection chain, aiding defense despite evolving payloads and infrastructure.

Reddit Discussion

r/Malware·posted by u/blackpointcyber
00

Tl:dr

  • Blackpoint’s Adversary Pursuit Group (APG) identified two previously undocumented .NET malware components delivered together through a ClickFix chain: RemotePanel, a persistent remote access platform, and BoundSiphon, a credential and cryptocurrency stealer.
  • RemotePanel establishes persistence by masquerading as the Windows Time service and gives operators broad control over infected systems, including PowerShell, file and process management, screen access, modular HVNC, and fleet management.
  • RemotePanel uses a BNB Smart Chain contract to resolve its active Command and Control (C2) server, allowing operators to rotate infrastructure without rebuilding or redeploying the RAT.
  • BoundSiphon runs primarily from memory and targets browser credentials and sessions, cryptocurrency wallets, password manager data, and selected documents, including secrets protected by Chromium App-Bound Encryption.
  • APG identified strong code and build overlap between BoundSiphon and a stealer previously documented by Socket, linking the sample to an earlier stealer codebase or builder lineage.
  • APG is seeking additional research and samples tied to RemotePanel, BoundSiphon, the AntiSNG implementation, Socket linked stealer activity, and the BNB Smart Chain resolver to help connect the remaining lineage and infrastructure gaps.
  • RemotePanel and BoundSiphon reflect a broader shift toward modular malware ecosystems that separate persistent access from data theft, allowing operators to replace infrastructure and individual components while retaining the underlying capabilities needed to continue an operation.
  • For victims, a single successful infection can lead to persistent remote access and theft of credentials, browser sessions, cryptocurrency wallets, password manager data, and other sensitive information, increasing the risk of account takeover, fraud, and continued compromise.
  • Blackpoint has detections in place for key behaviors across the infection chain, providing coverage even as individual payloads and infrastructure change.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 17:21:15 UTC

Technical Analysis

Blackpoint Cyber's Adversary Pursuit Group identified two .NET malware components, RemotePanel and BoundSiphon, delivered via five malicious NuGet packages impersonating Chinese .NET UI and infrastructure libraries. RemotePanel establishes persistence by masquerading as the Windows Time service and offers operators broad system control, including PowerShell, file/process management, screen access, modular HVNC, and fleet management. It uses a BNB Smart Chain contract to resolve its active C2 server, enabling infrastructure rotation without redeployment. BoundSiphon operates primarily in memory, stealing browser credentials, cryptocurrency wallets, password manager data, and protected documents. The malicious packages use .NET Reactor protection and JIT hooking to evade detection and execute payloads. The campaign targets developer workstations and CI/CD build servers, with approximately 65,000 downloads. The operator uses version rotation and unlisting to evade detection. The modular malware ecosystem allows operators to replace components while maintaining persistent access and data theft capabilities. Blackpoint Cyber has detections for key behaviors across the infection chain.

Potential Impact

Successful infection results in persistent remote access to affected systems and theft of sensitive data including browser credentials, cryptocurrency wallets, password manager data, and protected documents. This increases the risk of account takeover, fraud, and ongoing compromise of developer workstations and CI/CD infrastructure. The malware's use of blockchain-based C2 resolution and modular design complicates detection and remediation efforts.

Defensive Guidance

Blackpoint Cyber has detections in place for key behaviors across the infection chain, providing coverage despite evolving payloads and infrastructure. Users should remove the identified malicious NuGet packages and avoid installing packages from untrusted or suspicious sources, especially those impersonating Chinese .NET libraries. Monitor for unusual persistence mechanisms masquerading as legitimate services such as the Windows Time service. Follow vendor advisories and NuGet Gallery takedown notices for updates on package availability and remediation. Patch status is not yet confirmed — check the NuGet Gallery and vendor advisories for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
Malware
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":32,"reasons":["external_link","established_author"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ab7fefef7a7c5410687cb25

Added to database: 09/26/2026, 17:21:02 UTC

Last enriched: 09/26/2026, 17:21:15 UTC

Last updated: 09/27/2026, 03:17:43 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses