Skip to main content

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

0
Medium
Published: 08/11/2026 (08/11/2026, 16:14:21 UTC)
Source: AlienVault OTX General

Description

An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 09:33:46 UTC

Technical Analysis

This threat involves a multi-stage infection chain initiated by a ClickFix lure, which uses a legitimately signed IBM SPSS IDE and four decoy DLLs along with a date-formatting API as a trampoline to deploy the BabaDeda loader. The loader then delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant characterized by the absence of imports and runtime string construction. CNCMachineRMS provides operators with comprehensive remote control capabilities including an interactive shell, file management, screen capture, creation of privileged local accounts for backdoor access, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for both configuration and C2 traffic. The implant beacons to its C2 every 600 seconds and supports twenty typed commands to download and execute additional payloads, suggesting active operator involvement and potential for further malicious activity.

Potential Impact

The implant allows attackers to gain extensive remote access to compromised systems, including interactive shell access, file management, screen capture, and the ability to create privileged local accounts for persistent backdoor access. The presence of multiple persistence mechanisms and a custom scripting language enables attackers to maintain long-term control and execute a wide range of commands, potentially leading to significant operational impact. The implant's design supports hands-on-keyboard activity, increasing the risk of targeted follow-on attacks and data exfiltration.

Defensive Guidance

No official patch or remediation guidance is provided for this threat. Mitigation should focus on detecting and blocking the initial infection vector, such as the ClickFix lure, and monitoring for indicators of compromise related to the BabaDeda loader and CNCMachineRMS implant. Network defenders should implement detection rules for the implant's beaconing behavior and command patterns. Since this is a malware implant with no known exploits in the wild and no vendor patch, incident response should prioritize containment and eradication upon detection.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.levelblue.com/blogs/spiderlabs-blog/cncmachinerms-the-undocumented-rat-at-the-end-of-a-babadeda-chain"]
Pulse Id
6a7b4a5db787f887767b8a2a

Indicators of Compromise

Hash

ValueDescriptionCopy
hashb804b9dd2726e69fb4f496a6872f90edf9146ad8044c6d3a592040ce1074a5d0
—
hash5b71b49bad415643ff3e291ee3ba550e5edfd584eb913859dadb81634450e7e7
—
hash3d4e7187f74de912f9d52f5ba6a95bd41868348b16583d72957d732c0ed8f0e7
—
hash3466c3524f13cb3b7c87819e619bdb482ec9034a57bcdbe0240af6a9a530b02a
—
hash3b9b86feb3b789dda9cdfe5425ccb7e1feae9fde2cc158ff962991218a98f53f
—
hash2922837a8d049bf0b51f0f9b27340a377b27dd1912675e2cd82056db83ec7a19
—
hash744b8165b6161cbd1d5ecc423ecfdb8306485afdc80262000ab3c6908881ef9e
—
hashbb81786286be437b3ec6d562055767097c9277054e1d09172caa96376451481c
—
hash1db08732a7f63ba3487b10f7c13ebaaf
—
hash31c4eeb36c12d0784be6e21ee40a2b60
—
hash8dcb875c657f72e446d1ea88a1e8d82c
—
hash3aa2b2eacd07b23285baee2aad757c7094955bbf
—
hash3e9720f33a958795f9744517cde035c27f8d3764
—
hashc1b0f0243c5898161ac71ebaead265460d2e4077
—
hash1289b528f53c4b94f51a151ab1422797
—
hash14477fd8ce26e5251dddf34a003364bc
—
hash3d393f2bdb67d15602a96a1496a82942
—
hashbfb25270df49bb391193a59281d5ffcf
—
hash12529884496d55a7a9aa96765af4ea4257499fec
—
hash7530ac13140d3794ad5a6680ee88ff756c44717b
—
hashb42cfc33c90e2f2666e6a347969fea05ed09cae7
—
hashf2a5f6ad71f4c1dd1acd5dd003fc362516e36287
—
hash0562c588997fa9961d55c6ab1db2656344324bca8db9ea7b64fe309132b2399f
—

Threat ID: 6a7c3546bf8831d539491d3e

Added to database: 08/12/2026, 08:56:38 UTC

Last enriched: 08/12/2026, 09:33:46 UTC

Last updated: 09/24/2026, 19:14:34 UTC

Views: 139

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses