MALICIOUS (1) campaign cataloged at 2026-08-21(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-08-boto4¶
During installation, package executes an embedded executable. The executable is capable of executing remote commands, establishing persistence, cryptomining, exfiltrating basic data, further network scanning and worm-style propagation. Actions are controlled via a Telegram bot.
Abuse categories¶
basic_exfiltration
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
cryptominer
Campaign uses cryptominer.
network-scan
Campaign uses network-scan.
persistence
Campaign uses persistence.
remote_commands
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
uses-telegram-bot
Telegram Bot is used for malicious purposes
worm
Campaign uses worm.