Skip to main content

RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft

0
Medium
Published: 09/24/2026 (09/24/2026, 17:43:48 UTC)
Source: AlienVault OTX General

Description

Two previously undocumented .NET malware components were delivered through a ClickFix infection chain. RemotePanel establishes persistent remote access by masquerading as the Windows Time service, providing operators with PowerShell control, file and process management, screen access, modular HVNC, and fleet management capabilities. It uses a BNB Smart Chain contract to dynamically resolve its active Command and Control server, enabling infrastructure rotation without rebuilding the RAT. BoundSiphon runs primarily from memory, targeting browser credentials and sessions, cryptocurrency wallets, password manager data, and documents, including secrets protected by Chromium App-Bound Encryption. Strong code overlap exists between BoundSiphon and a stealer previously documented by Socket, linking the sample to an earlier stealer codebase. The modular design separates persistent access from data theft, allowing operators to replace infrastructure and individual components while maintaining operational capabilities.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 14:32:41 UTC

Technical Analysis

This threat consists of two previously undocumented .NET malware components: RemotePanel and BoundSiphon. RemotePanel establishes persistent remote access by impersonating the Windows Time service and provides operators with extensive control capabilities including PowerShell access, file and process management, screen sharing, modular hidden VNC, and fleet management. It leverages a BNB Smart Chain contract to dynamically resolve its active C2 server, facilitating infrastructure rotation without needing to rebuild the RAT. BoundSiphon is a memory-resident stealer targeting browser credentials, sessions, cryptocurrency wallets, password manager data, and protected documents, including those secured by Chromium App-Bound Encryption. Code overlap links BoundSiphon to an earlier stealer documented by Socket. The modular architecture allows operators to swap infrastructure and components independently while maintaining persistence and data theft capabilities. The infection vector is a ClickFix chain. No CVE or patch information is available, and no active exploitation is reported.

Potential Impact

The malware enables persistent remote access to infected systems, allowing attackers to control the system via PowerShell, manage files and processes, and capture screen content. It also facilitates credential theft from browsers, cryptocurrency wallets, password managers, and protected documents, potentially leading to credential compromise, financial theft, and data exfiltration. The use of a blockchain-based mechanism for C2 server resolution complicates detection and takedown efforts. The modular design enhances attacker flexibility and persistence. No known active exploitation has been reported at this time.

Defensive Guidance

No official patches or vendor advisories are available for this malware. Mitigation should focus on detection and removal of the malware components. Monitoring for indicators of compromise such as the provided domains, IP address, and file hashes is recommended. Network defenses should consider blocking communications to the identified domains and IP. Because the malware masquerades as the Windows Time service, verifying legitimate Windows services and monitoring for anomalous PowerShell activity can aid detection. Incident response should include credential resets and wallet security reviews if infection is confirmed. Patch status is not yet confirmed — check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://blackpointcyber.com/blog/remotepanel-and-boundsiphon-a-dual-payload-toolkit-for-persistent-access-and-browser-theft/"]
Pulse Id
6ab561541d94721ef4ce040e

Indicators of Compromise

Domain

ValueDescriptionCopy
domaingreatgrgreeng.com
—
domainleftsideegpeakk.com
—

Hash

ValueDescriptionCopy
hash30f9387b6aa2dd249d93cec58786251a224faaec57673a4b8104a33a01dfe62b
—
hash351f0d27d2f0105186446693eed5794419ad79d7e6e647fc2fe74dbffb25f9ad
—
hash5060c8184993d5ac04701ffa2c1d30451e40a7b2dbfc084eceaabb5084704991
—
hasha7e8c9e157d3ce37913a32aaa861b5248da4cc5288fa99a6b291524af5e3b9c6
—
hashb7a5c52cedd9cd5425a7f85b8d3b4b869b805c70c7991375a2c4ab612ff7906d
—
hashfec29bbd8e50b6635ef683f03f6e018c9627aa6362a2f167115424e50b8c1b10
—

Ip

ValueDescriptionCopy
ip193.233.75.7
—

Threat ID: 6ab6829bf7a7c54106df078e

Added to database: 09/25/2026, 14:18:03 UTC

Last enriched: 09/25/2026, 14:32:41 UTC

Last updated: 09/26/2026, 02:50:59 UTC

Views: 55

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses