A multistage .NET malware loader protected with KoiVM resurfaced in spam campaigns using ZIP attachments disguised as invoices or order documents. K7 Labs reported that the first-stage downloader decoded Hastebin-based C2 URLs, fetched a Base64-encoded and Deflate-compressed second-stage payload, and then XOR-decoded it with the hardcoded key M4use to reconstruct a KoiVM-virtualized dropper. The second stage was heavily obfuscated with ConfuserEx, an open-source .NET protector, complicating analysis and detection.
Depending on the command-and-control endpoint reached, the dropper unpacked and deployed either Agent Tesla or Remcos RAT, using XOR keys Jus3ify and Monito3 respectively; the Agent Tesla sample was also protected with .NET Reactor. The final payloads enabled keystroke logging, browser cookie theft, cryptocurrency wallet theft, screenshot capture, and remote command execution, giving operators broad surveillance and control over infected systems. The report also published supporting indicators of compromise, including file hashes, Hastebin C2 URLs, and a Remcos-linked IP address.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
The analysis found the stage-1 downloader decoded Hastebin C2 URLs, retrieved and XOR-decoded a KoiVM-virtualized stage-2 dropper, and then unpacked a final payload from resources. Depending on the retrieved payload, the malware deployed either Agent Tesla, which exfiltrated data via email, or Remcos RAT, which used an RC4-encrypted configuration and a listener at 172.111.234[.]110:5888.
K7 Labs published analysis of a multistage .NET malware loader delivered through spam ZIP attachments masquerading as invoices or orders. The campaign used Hastebin-hosted stage-2 payloads and ultimately deployed either Agent Tesla or Remcos RAT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.