CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.
AI Analysis
Technical Summary
This threat involves a multi-stage infection chain initiated by a ClickFix lure, which uses a legitimately signed IBM SPSS IDE and four decoy DLLs along with a date-formatting API as a trampoline to deploy the BabaDeda loader. The loader then delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant characterized by the absence of imports and runtime string construction. CNCMachineRMS provides operators with comprehensive remote control capabilities including an interactive shell, file management, screen capture, creation of privileged local accounts for backdoor access, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for both configuration and C2 traffic. The implant beacons to its C2 every 600 seconds and supports twenty typed commands to download and execute additional payloads, suggesting active operator involvement and potential for further malicious activity.
Potential Impact
The implant allows attackers to gain extensive remote access to compromised systems, including interactive shell access, file management, screen capture, and the ability to create privileged local accounts for persistent backdoor access. The presence of multiple persistence mechanisms and a custom scripting language enables attackers to maintain long-term control and execute a wide range of commands, potentially leading to significant operational impact. The implant's design supports hands-on-keyboard activity, increasing the risk of targeted follow-on attacks and data exfiltration.
Mitigation Recommendations
No official patch or remediation guidance is provided for this threat. Mitigation should focus on detecting and blocking the initial infection vector, such as the ClickFix lure, and monitoring for indicators of compromise related to the BabaDeda loader and CNCMachineRMS implant. Network defenders should implement detection rules for the implant's beaconing behavior and command patterns. Since this is a malware implant with no known exploits in the wild and no vendor patch, incident response should prioritize containment and eradication upon detection.
Indicators of Compromise
- hash: b804b9dd2726e69fb4f496a6872f90edf9146ad8044c6d3a592040ce1074a5d0
- hash: 5b71b49bad415643ff3e291ee3ba550e5edfd584eb913859dadb81634450e7e7
- hash: 3d4e7187f74de912f9d52f5ba6a95bd41868348b16583d72957d732c0ed8f0e7
- hash: 3466c3524f13cb3b7c87819e619bdb482ec9034a57bcdbe0240af6a9a530b02a
- hash: 3b9b86feb3b789dda9cdfe5425ccb7e1feae9fde2cc158ff962991218a98f53f
- hash: 2922837a8d049bf0b51f0f9b27340a377b27dd1912675e2cd82056db83ec7a19
- hash: 744b8165b6161cbd1d5ecc423ecfdb8306485afdc80262000ab3c6908881ef9e
- hash: bb81786286be437b3ec6d562055767097c9277054e1d09172caa96376451481c
- hash: 1db08732a7f63ba3487b10f7c13ebaaf
- hash: 31c4eeb36c12d0784be6e21ee40a2b60
- hash: 8dcb875c657f72e446d1ea88a1e8d82c
- hash: 3aa2b2eacd07b23285baee2aad757c7094955bbf
- hash: 3e9720f33a958795f9744517cde035c27f8d3764
- hash: c1b0f0243c5898161ac71ebaead265460d2e4077
- hash: 1289b528f53c4b94f51a151ab1422797
- hash: 14477fd8ce26e5251dddf34a003364bc
- hash: 3d393f2bdb67d15602a96a1496a82942
- hash: bfb25270df49bb391193a59281d5ffcf
- hash: 12529884496d55a7a9aa96765af4ea4257499fec
- hash: 7530ac13140d3794ad5a6680ee88ff756c44717b
- hash: b42cfc33c90e2f2666e6a347969fea05ed09cae7
- hash: f2a5f6ad71f4c1dd1acd5dd003fc362516e36287
- hash: 0562c588997fa9961d55c6ab1db2656344324bca8db9ea7b64fe309132b2399f
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
Description
An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a multi-stage infection chain initiated by a ClickFix lure, which uses a legitimately signed IBM SPSS IDE and four decoy DLLs along with a date-formatting API as a trampoline to deploy the BabaDeda loader. The loader then delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant characterized by the absence of imports and runtime string construction. CNCMachineRMS provides operators with comprehensive remote control capabilities including an interactive shell, file management, screen capture, creation of privileged local accounts for backdoor access, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for both configuration and C2 traffic. The implant beacons to its C2 every 600 seconds and supports twenty typed commands to download and execute additional payloads, suggesting active operator involvement and potential for further malicious activity.
Potential Impact
The implant allows attackers to gain extensive remote access to compromised systems, including interactive shell access, file management, screen capture, and the ability to create privileged local accounts for persistent backdoor access. The presence of multiple persistence mechanisms and a custom scripting language enables attackers to maintain long-term control and execute a wide range of commands, potentially leading to significant operational impact. The implant's design supports hands-on-keyboard activity, increasing the risk of targeted follow-on attacks and data exfiltration.
Defensive Guidance
No official patch or remediation guidance is provided for this threat. Mitigation should focus on detecting and blocking the initial infection vector, such as the ClickFix lure, and monitoring for indicators of compromise related to the BabaDeda loader and CNCMachineRMS implant. Network defenders should implement detection rules for the implant's beaconing behavior and command patterns. Since this is a malware implant with no known exploits in the wild and no vendor patch, incident response should prioritize containment and eradication upon detection.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.levelblue.com/blogs/spiderlabs-blog/cncmachinerms-the-undocumented-rat-at-the-end-of-a-babadeda-chain"]
- Pulse Id
- 6a7b4a5db787f887767b8a2a
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashb804b9dd2726e69fb4f496a6872f90edf9146ad8044c6d3a592040ce1074a5d0 | — | |
hash5b71b49bad415643ff3e291ee3ba550e5edfd584eb913859dadb81634450e7e7 | — | |
hash3d4e7187f74de912f9d52f5ba6a95bd41868348b16583d72957d732c0ed8f0e7 | — | |
hash3466c3524f13cb3b7c87819e619bdb482ec9034a57bcdbe0240af6a9a530b02a | — | |
hash3b9b86feb3b789dda9cdfe5425ccb7e1feae9fde2cc158ff962991218a98f53f | — | |
hash2922837a8d049bf0b51f0f9b27340a377b27dd1912675e2cd82056db83ec7a19 | — | |
hash744b8165b6161cbd1d5ecc423ecfdb8306485afdc80262000ab3c6908881ef9e | — | |
hashbb81786286be437b3ec6d562055767097c9277054e1d09172caa96376451481c | — | |
hash1db08732a7f63ba3487b10f7c13ebaaf | — | |
hash31c4eeb36c12d0784be6e21ee40a2b60 | — | |
hash8dcb875c657f72e446d1ea88a1e8d82c | — | |
hash3aa2b2eacd07b23285baee2aad757c7094955bbf | — | |
hash3e9720f33a958795f9744517cde035c27f8d3764 | — | |
hashc1b0f0243c5898161ac71ebaead265460d2e4077 | — | |
hash1289b528f53c4b94f51a151ab1422797 | — | |
hash14477fd8ce26e5251dddf34a003364bc | — | |
hash3d393f2bdb67d15602a96a1496a82942 | — | |
hashbfb25270df49bb391193a59281d5ffcf | — | |
hash12529884496d55a7a9aa96765af4ea4257499fec | — | |
hash7530ac13140d3794ad5a6680ee88ff756c44717b | — | |
hashb42cfc33c90e2f2666e6a347969fea05ed09cae7 | — | |
hashf2a5f6ad71f4c1dd1acd5dd003fc362516e36287 | — | |
hash0562c588997fa9961d55c6ab1db2656344324bca8db9ea7b64fe309132b2399f | — |
Threat ID: 6a7c3546bf8831d539491d3e
Added to database: 08/12/2026, 08:56:38 UTC
Last enriched: 08/12/2026, 09:33:46 UTC
Last updated: 09/24/2026, 19:14:34 UTC
Views: 139
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.