BORZ is a previously unreported command-and-control (C2) panel family associated with a reported malware campaign observed on infrastructure at 94.232.46[.]16. In the described activity, a dual-process loader launched a legitimate Slack desktop application as a decoy while downloading a second-stage payload from hxxp://94.232.46[.]16:8081/dl. The payload reportedly established persistence on the infected host, dropped a text artifact containing the string "Khorramshahr-4 loaded," and communicated with C2 infrastructure on ports 27015 and 27016. The BORZ admin panel was exposed at hxxp://94.232.46[.]16:8081/login, and port 8081/TCP was identified as hosting both the HTTP C2 panel and payload distribution endpoint. The report notes that ports 27015 and 27016 are Valve Source Engine game server ports that may have been repurposed for botnet C2, covert communications, or DDoS-related activity. The infrastructure was associated with AS48080, registered to Dmitriy Panchenko in Moscow, Russian Federation, and the surrounding 94.232.46.0/24 range showed extensive abuse history, including neighboring IPs with large AbuseIPDB report counts and an association in the range with RocketCloud.ru, suggesting possible reseller or bulletproof hosting characteristics. As of 2026-04-17, the /dl payload endpoint and BORZ panel were offline and refusing connections. No overlap was found with existing IOC databases or prior investigations cited in the content, and no confirmed link was established to known Iranian APT groups despite the "Khorramshahr-4" reference. The reporting assessed the activity most likely as a false-flag or multinational hacktivist operation, with a secondary possibility of a cybercriminal botnet operator using provocative theming. High-confidence indicators mentioned in the content include 94.232.46[.]16, hxxp://94.232.46[.]16:8081/login, hxxp://94.232.46[.]16:8081/dl, ports 8081, 27015, and 27016, the use of Slack as a decoy process, and the artifact string "Khorramshahr-4 loaded."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Command and Control Application Layer Protocol T1071 C2 via port 8081 HTTP
Command and Control Ingress Tool Transfer T1105 Payload download from /dl endpoint
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom or emerging command-and-control framework/panel used in a dual-process loader campaign. It serves payloads from /dl, uses Slack as a decoy, establishes persistence, and communicates with C2 over ports 27015 and 27016, likely for botnet-style control or covert communications.
BORZ is described as a previously unreported custom or emerging C2 panel/framework used in a dual-process loader campaign. It delivers a second-stage payload from /dl, establishes persistence, drops a text artifact containing "Khorramshahr-4 loaded," and communicates with C2 over ports 27015 and 27016, likely for botnet-style command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.