Exposed Open Directory Leaks BYOB Framework Across Windows, Linux, and macOS
Recent investigations have revealed the presence of an active command and control server operating a complete deployment of the BYOB framework, following the identification of an exposed open directory.
Recent investigations have revealed the presence of an active command and control server operating a complete deployment of the BYOB framework, following the identification of an exposed open directory.
The server, with the IP address 38.255.43.60 on port 8081, has been distributing malicious payloads aimed at establishing persistent remote access across systems running Windows, Linux, and macOS.
Hosted by Hyonix in the United States, the infrastructure comprises various components like droppers, stagers, and post-exploitation modules, enabling attackers to maintain control over compromised devices.
The framework presents notable risks through a multi-stage infection process that evades detection while providing surveillance and control capabilities.
The framework employs a three-stage infection process. Initial Stage: A 359-byte dropper uses Base64 encoding, Zlib compression, and Marshal deserialization for obfuscation. Second Stage: A 2 KB stager performs anti-virtual machine checks. Final Payload: A 123 KB Remote Access Trojan establishes encrypted HTTP communications and loads additional modules.
The framework presents notable risks through a multi-stage infection process that evades detection while providing surveillance and control capabilities.
Windows: Registry run keys, URL shortcut files, scheduled tasks, and WMI subscriptions. Linux: Malicious crontab entries. macOS: LaunchAgent property list files.
The BYOB payload offers extensive surveillance capabilities through modular components:
Keylogger: Captures keystrokes and active window names using platform-specific hooks. Packet Sniffer: Intercepts network traffic to extract data. Outlook Harvesting: Accesses Microsoft Outlook without authentication to extract emails.
Analysis indicates the framework has been operational since at least March 2024, with nodes distributed across Singapore, Panama, and the United States. This suggests organized planning and resource allocation by threat actors.
Additional findings revealed dual-purpose infrastructure with some command and control nodes also hosting cryptocurrency mining software, indicating a financially motivated campaign.
Based on reporting by Cyber Security News.
