Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

One leftover build path links an infostealer, a remote-access tool, and a ransomware family

0
Medium
Published: 09/01/2026 (09/01/2026, 22:50:50 UTC)
Source: AlienVault OTX General

Description

A compilation artifact, specifically a developer's home directory path (/home/tcherber/.cargo/), linked multiple malware families including a Rust-based infostealer named Zer0day Stealer, an HVNC remote-control tool, and ENIGMA Locker ransomware to a single developer. The infostealer exfiltrates cryptocurrency wallets, browser credentials, Office documents, and VPN configurations. The HVNC tool enables hidden remote desktop sessions and implements AMSI and ETW evasion techniques. Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS. Multiple droppers written in C, Rust, and PowerShell were discovered delivering the malicious payloads. Build timestamps indicated development occurred within weeks, and infrastructure leaked evidence of additional tools including FUD-Crypter, Botnet, and C2 Agent components, demonstrating how overlooked compilation artifacts enable comprehensive attribution and threat mapping.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.vmray.com/news/one-leftover-build-path-links-an-infostealer-a-remote-access-tool-and-a-ransomware-family/"]
Adversary
null
Pulse Id
6a9756cad8fd625876d6a1a5
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip93.152.223.30
ip93.152.220.87

Hash

ValueDescriptionCopy
hashd222549235db4112333d82e12f767d47
hash12463a81a786b04fe4b3b7d1aa1222e589e5921d
hash178f890f62db90738b11300dd272537240b1c8a599d2ebeccdea01654811fed0
hash278762dfc0f743216a475919bdc9ecc59735bcc247bba5b7b468fc475407ec6a
hash6aef80514237808dfe25621a8912422d20a8414bc2054008a119e541166821b5
hash6bddf59e2a5065255cfc90d2e2e66e3bfd4a7cbf4e0b6341b4da93b574cc4f53
hash7cb59abaa268ac66461447773d46bb0b0e5e2568e35e1a8f1d07ac2ec57f67a6
hashabd43578b135df61f49844087af0b372ae10b2f27721ad6ba09710760ab0b240
hashd0f0734d4e31ec126da43a46896d0cd761e5532c0c385db6226cc5a6927d7722
hashf9964a8d9d01052d9bebe057deadd7ce9d794e8296e2a72229f8ae4aa62ae224
hashfad8f76afec90c888b4a739539deae250320fd49c34ef8458833b356ea9b7767

Threat ID: 6a984d43acd9273b4973cd57

Added to database: 09/02/2026, 16:22:27 UTC

Last updated: 09/02/2026, 22:31:12 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses