Skip to content

MALICIOUS (1) campaign cataloged at 2026-08-21(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-08-boto4

During installation, package executes an embedded executable. The executable is capable of executing remote commands, establishing persistence, cryptomining, exfiltrating basic data, further network scanning and worm-style propagation. Actions are controlled via a Telegram bot.

Abuse categories

basic_exfiltration

The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

cryptominer

Campaign uses cryptominer.

network-scan

Campaign uses network-scan.

persistence

Campaign uses persistence.

remote_commands

The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

uses-telegram-bot

Telegram Bot is used for malicious purposes

worm

Campaign uses worm.

Packages in the campaign

campaign:2026-08-boto4