MALICIOUS (1) campaign cataloged at 2026-05-26(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-05-helu¶
During import, the hidden code downloads and executes the second-stage code. After performing anti-analysis checks, it downloads a malicious executable and ensures its persistence.
Abuse categories¶
covering-tracks
The package contains code to cover its tracks, e.g. by deleting malicious code after execution.
malware
Package contains or installs known malware.
obfuscation
Code uses obfuscation techniques to hide its true purpose.
persistence
Campaign uses persistence.
remote_executable
Downloads and executes a remote executable.
remote_script
Downloads and executes a remote malicious script.
sandbox-detection
The package contains code to detect if it is running in a sandbox environment.
References¶
Referenced resources may include blog posts about the campaign, malware analysis, sandbox reports, or other relevant information.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
-
hxxps://raw.githubusercontent.com/jjinkjimmy-design/i-belive-i-can-fly/refs/heads/main/stg2.py -
hxxps://learn-python-beginner-hub.netlify.app/Runtime-Broker.exe -
hxxps://tranquil-lollipop-6e2f41.netlify.app/cbi.json