Palo Alto Networks Unit 42 reported that an njRAT campaign used Pastebin as a pseudo-command-and-control channel and staging service to distribute second-stage malware. The activity had been observed since at least October 2020, with njRAT downloaders pulling payloads or configuration data from Pastebin instead of relying solely on attacker-controlled infrastructure, a tactic that can help blend malicious traffic with legitimate web activity and complicate blocking efforts.
Researchers said the malware retrieved content through several methods, including base64, reversed base64, hex-to-base64 conversion, gzip-compressed base64, direct URL references, JSON, and HTML parsing. In multiple cases, the second-stage payloads were 32-bit .NET executables with Trojan and keylogging functionality, and one sample used Pastebin to direct victims to a remote executable hosted at textfiles[.]us; the report also included related hashes, Pastebin URLs, and vendor detection coverage for the campaign.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported that malware authors had used njRAT, also known as Bladabindi, since at least October 2020 to retrieve second-stage payloads and configuration data from Pastebin. The activity used Pastebin as a public hosting and pseudo-command-and-control service to avoid maintaining attacker-owned C2 infrastructure.
Unit 42 published research describing multiple njRAT delivery patterns that pulled malicious content from Pastebin in formats including base64, reversed base64, hex, gzip-compressed blobs, JSON, direct links, and HTML-parsed pages. The report said the Pastebin tunnel remained active and provided hashes, Pastebin URLs, and detection coverage for the campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 76 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.