BYOB (Build Your Own Botnet) is a cross-platform post-exploitation framework and Remote Access Trojan deployment observed being served from exposed command-and-control infrastructure. Reporting describes a complete BYOB deployment hosted on an active C2 server at 38[.]255[.]43[.]60:8081, including droppers, stagers, payloads, and post-exploitation modules targeting Windows, Linux, and macOS. The infection chain is described as a three-stage Python workflow: a small obfuscated dropper using Base64 encoding, zlib compression, and marshal deserialization; a second-stage stager that performs anti-virtual-machine checks by inspecting environment variables and process names associated with VirtualBox, VMware, Hyper-V, and XenServer; and a final-stage payload, approximately 123 KB, that functions as a RAT communicating over encrypted HTTP and loading additional modules on demand. Documented capabilities include host and network reconnaissance, keylogging using pyHook on Windows and pyxhook on Unix-like systems, packet sniffing via raw sockets, screenshot capture, and Outlook email harvesting through Windows COM automation against an already authenticated Outlook session. Persistence mechanisms were reported across all three supported operating systems, including Windows Registry Run keys disguised as "Java-Update-Manager," Startup folder URL shortcut files, hourly scheduled tasks, WMI event subscription-based execution, Linux crontab persistence, and macOS LaunchAgent property list files. A Windows privilege escalation component was also reported to invoke ShellExecuteEx with the "runas" verb, triggering a UAC prompt. Hunt.io researchers stated the infrastructure had been active since at least March 2024 and identified additional nodes in the United States, Singapore, and Panama. Two of five identified C2 nodes were also reported to host XMRig, suggesting some infrastructure was used for both remote access operations and cryptomining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage, cross-platform post-exploitation framework that deploys a RAT for persistent remote access and on-demand surveillance modules (e.g., keylogging, packet sniffing, Outlook email harvesting), using obfuscated droppers/stagers, anti-VM checks, encrypted HTTP C2, and multiple OS-specific persistence mechanisms.
A cross-platform post-exploitation framework delivering a multi-stage infection chain (dropper → stager → RAT) to establish persistent remote access and load modular surveillance capabilities (e.g., keylogging, packet sniffing, Outlook email harvesting), with encrypted HTTP C2 communications and multiple OS-specific persistence mechanisms.
A modular, multi-stage Python-based remote access trojan/post-exploitation framework with droppers and stagers that fetch an encrypted RAT payload, supports cross-platform (Windows/Linux/macOS) persistence and post-exploitation modules (keylogging, screenshots, packet capture, Outlook email harvesting), and uses HTTP-based C2 with encrypted communications and modular payload delivery.
Python-based, modular, multi-stage remote access framework (dropper → stager → full payload) supporting Windows/Linux/macOS. Provides encrypted HTTP C2, dynamic module loading, persistence (registry run keys, startup folder, scheduled tasks, WMI, crontab, LaunchAgents), and post-exploitation capabilities including keylogging, screenshots, packet capture, process manipulation, Outlook email harvesting, and UAC elevation prompting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.