This week's OTX pulse cluster paints a coherent picture of a maturing credential-theft economy: five distinct operations, all converging on the same monetization objective — harvested credentials, browser session data, and enterprise network access for resale or downstream fraud.
Lunex Stealer (AlienVault/Ontinue) represents the cutting edge of stealer tradecraft: a four-stage chain beginning with fake CAPTCHA pages targeting Ukrainian-speaking users, escalating to kernel-level defense evasion via Bring Your Own Vulnerable Driver (BYOVD) using AMD's vulnerable PDFWKRNL.sys (CVE-2023-20598). Once EDR visibility is blinded at the kernel level, LunexLoader deploys LunexStealer, which rips credentials from seven Chromium-based browsers using custom SQL queries against browser SQLite stores and abuses native messaging hosts for browser hijacking.
Operation Master (actor: masterblack, SOCRadar) is the industrial-scale counterpart: a multi-tiered intrusion and monetization pipeline that scanned 277.5 million addresses to curate 81 high-value targets across 16 countries and 7 industries. Initial access rides a Palo Alto GlobalProtect authentication bypass (CVE-2026-0257), supplemented by a broad exploit kit (CVE-2022-40684 FortiOS, CVE-2024-1086 Linux kernel, CVE-2021-4034 PwnKit, CVE-2020-1938 Ghostcat, CVE-2021-36260 Hikvision, CVE-2023-7028 GitLab). Post-exploitation uses the AdaptixC2 framework, DNS tunneling for C2, SQL injection with xp_cmdshell for database theft, OAuth device-code phishing, and an invoice-fraud monetization platform.
Kothamine Agent (Malwarebytes) is an undocumented 30+ command RAT distributed via malicious npm packages, evading network detection by tunneling C2 through Tailscale's tailcat — legitimate mesh-VPN infrastructure that blends with sanctioned traffic. Variants include browser data theft and camera/microphone capture.
The Stealer Factory (K7 Labs) is a Python-based MaaS builder lowering the barrier to entry: operators generate customized Nuitka/PyInstaller-compiled Windows stealers with anti-VM checks, XOR+Base64-obfuscated webhook exfiltration configuration, and automatic dependency installation. Expect a long tail of low-sophistication variants from this builder.
PureRAT/PureLogs Japan Campaign (ITOCHU) rounds out the set: Japanese and Korean-language phishing lures disguised as product-damage complaints deliver ZIP archives with double-extension executables, DLL sideloading, Donut shellcode loading, process hollowing, and — again — BYOVD for defense evasion, culminating in PureRAT and the PureLogs stealer.
Collective assessment: BYOVD is no longer an APT-exclusive technique — it appears in two of five pulses. Legitimate-infrastructure C2 (Tailscale, webhooks, DNS tunneling, native messaging hosts) is the dominant evasion pattern. Browser credential stores remain the primary target across all stealer families.
Threat Actor / Malware Profile
Lunex Stealer / LunexLoader / PDFWKRNL
- Distribution: Fake CAPTCHA verification pages targeting Ukrainian-speaking users; social-engineered execution chain.
- Payload behavior: Four-stage chain. Stage progression culminates in LunexStealer extracting credentials, cookies, and autofill data from seven Chromium-based browsers via custom SQL against
Login Data/Web DataSQLite databases. Browser hijacking via Chrome native messaging host registration. - Anti-analysis / defense evasion: BYOVD — drops and loads the legitimately signed but vulnerable AMD driver
PDFWKRNL.sys(CVE-2023-20598) to terminate or blind kernel-level security monitoring before payload deployment. - C2: Observed infrastructure includes 194.165.16.55 and 31.76.103.132.
Operation Master (masterblack) / AdaptixC2
- Distribution / initial access: Mass scanning (277.5M IPs) → curated exploitation of perimeter appliances, led by GlobalProtect auth bypass CVE-2026-0257; supplementary exploits for FortiOS, Hikvision, Linux kernel, GitLab, and Tomcat AJP.
- Payload behavior: AdaptixC2 beacons for hands-on control; SQL injection with
xp_cmdshellto exfiltrate databases from 9+ MSSQL instances; OAuth device-code phishing for identity compromise; invoice-fraud platform for monetization. - C2: DNS tunneling for low-and-slow beaconing; C2 node 91.92.241.184.
- Persistence: AdaptixC2 implant persistence plus valid-account abuse from phished OAuth tokens.
Kothamine Agent
- Distribution: Malicious npm packages (supply-chain vector targeting developers/technology sector).
- Payload behavior: 30+ remote commands — command execution, file manipulation, plugin/capability extension; browser data theft; camera and microphone recording in some variants.
- C2: Encrypted C2 tunneled through Tailscale's
tailcatutility, hiding inside legitimate WireGuard-based mesh VPN traffic.
Python MaaS Stealer Builder
- Distribution: MaaS model — customers generate their own binaries; distribution varies by operator (phishing, cracks, malvertising).
- Payload behavior: Browser data extraction, anti-VM checks, webhook-based exfiltration (Discord/Telegram-style) with XOR + Base64 encoded configuration.
- Anti-analysis: Nuitka or PyInstaller compilation producing large, unpacked-looking executables that evade signature and some heuristic engines.
PureRAT / PureLogs (Japan campaign)
- Distribution: Japanese/Korean phishing emails themed as product-damage complaints → fake document-sharing sites → ZIP archives with double-extension executables (e.g.,
.pdf.exe). - Payload behavior: DLL sideloading chains, Donut in-memory shellcode loader, process hollowing into legitimate processes; PureRAT for remote control, PureLogs for credential/log harvesting.
- Anti-analysis: BYOVD driver deployment for EDR tampering; process hollowing to masquerade as trusted binaries.
- C2: Infrastructure on 103.153.74.201, 103.179.188.236 and domains including baoquocgiavn.com, bayareakajabe.com, bartonaussies.com.
IOC Analysis
The 172 indicators across these pulses break down into four operational classes:
- IPv4 addresses (194.165.16.55, 31.76.103.132, 91.92.241.184, 103.153.74.201, 103.179.188.236): C2 and staging infrastructure. Push to egress firewall/proxy block lists and retro-hunt 90 days of NetFlow/proxy logs. Note that stealer C2 churns fast — IP blocks are a snapshot control, not a durable one.
- Domains (PureRAT campaign infrastructure): Block at DNS resolver (RPZ) and secure web gateway. ThePureRAT domains follow a disposable, thematically random registration pattern — alert on newly registered domains (<30 days) matching phishing lure context.
- File hashes (MD5/SHA1/SHA256 for Lunex, Kothamine, Stealer Factory, PureRAT samples): Load into EDR blocklists and your TI platform (MISP, OpenCTI, or direct OTX integration via the API/SDK). SHA256 values are the reliable pivots; MD5/SHA1 are provided for legacy tool compatibility.
- CVEs: This is the highest-value indicator class. CVE-2023-20598 (AMD driver — add
PDFWKRNL.systo your vulnerable-driver blocklist per Microsoft's recommended driver block rules), CVE-2026-0257 (GlobalProtect — patch/emergency mitigations immediately if applicable), CVE-2022-40684, CVE-2024-1086, CVE-2021-4034, CVE-2020-1938, CVE-2021-36260, CVE-2022-28368, CVE-2023-7028. Cross-reference against your attack surface management inventory — Operation Master is actively scanning for these.
Tooling: OTX indicators decode natively into MISP/STIX via the OTX DirectConnect API. For the Donut shellcode loader in the PureRAT chain, use donut-decryptor or Mandiant's speakeasy for emulation; XOR-encoded webhook configs in the Python stealers yield to CyberChef (XOR brute-force + Base64 recipe). Browser Login Data extraction attempts are best caught behaviorally — not by hash.
Detection Engineering
---
title: BYOVD Vulnerable AMD Driver Load - PDFWKRNL
id: 9f2a1b3e-7c4d-4e8a-b1f2-lunexbyovd0001
status: experimental
description: Detects load or creation of the vulnerable AMD PDFWKRNL.sys driver used by Lunex Stealer and PureRAT campaigns for BYOVD defense evasion (CVE-2023-20598)
author: Security Arsenal Threat Intelligence
date: 2026/09/28
references:
- https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd
logsource:
category: driver_load
product: windows
detection:
selection_name:
ImageLoaded|endswith: '\PDFWKRNL.sys'
selection_hash:
Hashes|contains:
- '6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1'
selection_unsigned:
Signed: 'false'
condition: selection_name or selection_hash or (selection_name and selection_unsigned)
falsepositives:
- Legitimate AMD software installations (rare on servers)
level: high
tags:
- attack.defense_evasion
- attack.t1068
- attack.t1562.001
---
title: Chromium Browser Credential Database Access by Non-Browser Process
id: 1a4b7c2d-8e5f-4a9b-c2d3-stealersql00002
status: experimental
description: Detects non-browser processes accessing Chromium Login Data/Cookies SQLite stores - common to Lunex, PureLogs, and Python MaaS stealers
author: Security Arsenal Threat Intelligence
date: 2026/09/28
references:
- https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd
- https://labs.k7computing.com/index.php/the-stealer-factory-unpacking-a-python-based-maas-infostealer-builder
logsource:
category: file_access
product: windows
detection:
selection_files:
TargetFilename|contains:
- '\AppData\Local\Google\Chrome\User Data\'
- '\AppData\Local\Microsoft\Edge\User Data\'
- '\AppData\Local\BraveSoftware\Brave-Browser\User Data\'
- '\AppData\Roaming\Opera Software\'
selection_targets:
TargetFilename|endswith:
- '\Login Data'
- '\Cookies'
- '\Web Data'
- '\Local State'
filter_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\brave.exe'
- '\opera.exe'
condition: selection_files and selection_targets and not filter_browsers
falsepositives:
- Legitimate password managers and backup software
level: high
tags:
- attack.credential_access
- attack.t1555.003
---
title: Tailscale Tailcat or DNS Tunneling C2 via Legitimate Infrastructure
id: 7d3e9f1a-2b6c-4d7e-a3f4-kothaminec200003
status: experimental
description: Detects execution of tailcat/tailscale by unauthorized processes (Kothamine Agent) and suspicious DNS query volume consistent with AdaptixC2 DNS tunneling
author: Security Arsenal Threat Intelligence
date: 2026/09/28
references:
- https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
- https://socradar.io/blog/operation-master-intrusion-monetization-pipeline
logsource:
category: process_creation
product: windows
detection:
selection_tailcat:
Image|endswith:
- '\tailcat.exe'
- '\tailscaled.exe'
ParentImage|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\node.exe'
- '\wscript.exe'
- '\rundll32.exe'
selection_double_ext:
CommandLine|contains:
- '.pdf.exe'
- '.doc.exe'
- '.xlsx.exe'
selection_npm_child:
ParentImage|endswith: '\node.exe'
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\tailcat.exe'
condition: 1 of selection_*
falsepositives:
- Sanctioned Tailscale deployments - baseline and whitelist approved install paths
- Developers running npm tooling
level: medium
tags:
- attack.command_and_control
- attack.t1101
- attack.t1071.004
- attack.t1219
// Security Arsenal - Infostealer & C2 Infrastructure Hunt (Lunex / Operation Master / PureRAT / Kothamine)
// Hunt window: adjust as needed
let Lookback = 14d;
let C2IPs = dynamic(["194.165.16.55","31.76.103.132","91.92.241.184","103.153.74.201","103.179.188.236"]);
let BadDomains = dynamic(["baoquocgiavn.com","bayareakajabe.com","bartonaussies.com"]);
let BadHashes = dynamic([
"6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1",
"ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0",
"74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c",
"5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946"]);
// 1) Network connections to known C2
let NetHits = DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where RemoteIP in~ (C2IPs) or RemoteUrl in~ (BadDomains)
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort;
// 2) Vulnerable driver / stealer hash execution
let FileHits = DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where SHA256 in~ (BadHashes)
or ProcessCommandLine has_any ("PDFWKRNL","tailcat","Login Data",".pdf.exe")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName;
// 3) Browser credential store access by suspicious processes
let CredAccess = DeviceFileEvents
| where Timestamp > ago(Lookback)
| where FileName in~ ("Login Data","Cookies","Web Data","Local State")
| where FolderPath has_any ("\\Chrome\\User Data\\","\\Edge\\User Data\\","\\Brave-Browser\\")
| where not(InitiatingProcessFileName in~ ("chrome.exe","msedge.exe","brave.exe"))
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FolderPath, FileName;
union NetHits, FileHits, CredAccess
| sort by Timestamp desc
# Security Arsenal - Lunex/PureRAT/Stealer-Factory IOC Hunt
# Run as Administrator on endpoints or via your RMM/EDR script module
$ErrorActionPreference = 'SilentlyContinue'
$Report = @()
# 1) Vulnerable BYOVD driver presence (Lunex / PureRAT - CVE-2023-20598)
$DriverPaths = @("$env:SystemRoot\System32\drivers\PDFWKRNL.sys", "$env:TEMP\PDFWKRNL.sys")
foreach ($p in $DriverPaths) {
if (Test-Path $p) {
$h = (Get-FileHash $p -Algorithm SHA256).Hash
$Report += [PSCustomObject]@{Check='BYOVD Driver'; Finding=$p; Detail="SHA256: $h"}
}
}
Get-CimInstance Win32_SystemDriver | Where-Object { $_.Name -match 'PDFWKRNL' } | ForEach-Object {
$Report += [PSCustomObject]@{Check='Loaded Vuln Driver'; Finding=$_.Name; Detail=$_.PathName}
}
# 2) Chrome Native Messaging Host hijack artifacts (Lunex browser hijacking)
$NMH = 'HKLM:\SOFTWARE\Google\Chrome\NativeMessagingHosts','HKCU:\SOFTWARE\Google\Chrome\NativeMessagingHosts'
foreach ($key in $NMH) {
Get-ChildItem $key | ForEach-Object {
$manifest = (Get-ItemProperty $_.PSPath).'(default)'
if ($manifest -and $manifest -notmatch 'Google|Microsoft') {
$Report += [PSCustomObject]@{Check='Suspicious NativeMessagingHost'; Finding=$_.PSChildName; Detail=$manifest}
}
}
}
# 3) Unauthorized Tailscale/tailcat install (Kothamine C2 channel)
$tail = Get-Process tailscaled,tailscale -ErrorAction SilentlyContinue
if ($tail) { $Report += [PSCustomObject]@{Check='Tailscale Process Running'; Finding=$tail.Name -join ','; Detail='Verify against approved software inventory'} }
Get-ChildItem "$env:LOCALAPPDATA\Tailscale","$env:ProgramFiles\Tailscale" -ErrorAction SilentlyContinue | ForEach-Object {
$Report += [PSCustomObject]@{Check='Tailscale Install'; Finding=$_.FullName; Detail='Confirm authorized deployment'}
}
# 4) Double-extension executables in user-writable dirs (PureRAT phishing ZIPs)
Get-ChildItem "$env:USERPROFILE\Downloads","$env:TEMP" -Recurse -Include *.pdf.exe,*.doc.exe,*.xlsx.exe -ErrorAction SilentlyContinue | ForEach-Object {
$Report += [PSCustomObject]@{Check='Double-Extension Executable'; Finding=$_.FullName; Detail="Created: $($_.CreationTime)"}
}
# 5) Known C2 connections (established or recent)
$C2 = '194.165.16.55','31.76.103.132','91.92.241.184','103.153.74.201','103.179.188.236'
Get-NetTCPConnection -State Established | Where-Object { $C2 -contains $_.RemoteAddress } | ForEach-Object {
$proc = (Get-Process -Id $_.OwningProcess).ProcessName
$Report += [PSCustomObject]@{Check='ACTIVE C2 CONNECTION'; Finding=$_.RemoteAddress; Detail="Process: $proc (PID $($_.OwningProcess))"}
}
# 6) Known malware hashes in common staging locations
$BadHashes = '3f4c9025125027e307b7e52dd577303b','41ff3ecd1458b0bf86e1b4891636213e','b96d75a000367c200958089728fc5cb8','82699276b0f59a2304120a6baaf64a6b','429ed63ab3fbda8d22d0ac750ecfe8cc'
Get-ChildItem "$env:TEMP","$env:USERPROFILE\Downloads","$env:APPDATA" -Recurse -File -ErrorAction SilentlyContinue |
Where-Object { $_.Length -lt 50MB } | ForEach-Object {
if ($BadHashes -contains (Get-FileHash $_.FullName -Algorithm MD5).Hash.ToLower()) {
$Report += [PSCustomObject]@{Check='KNOWN MALWARE HASH'; Finding=$_.FullName; Detail='Isolate host immediately'}
}
}
$Report | Format-Table -AutoSize
if (-not $Report) { Write-Host '[+] No indicators of compromise found.' -ForegroundColor Green }
else { Write-Host "[!] $($Report.Count) finding(s) - escalate to IR." -ForegroundColor Red }
Response Priorities
Immediate (0–4 hours):
- Block all C2 IPs (194.165.16.55, 31.76.103.132, 91.92.241.184, 103.153.74.201, 103.179.188.236) and PureRAT domains at egress firewall, proxy, and DNS resolver.
- Push the SHA256/MD5 hash sets to EDR blocklists; deploy the Sigma rules and run the KQL hunt across a 14–30 day lookback.
- Verify
PDFWKRNL.sysis on your vulnerable-driver blocklist (Microsoft VBS driver block rules or EDR equivalents) — two separate campaigns are weaponizing it. - Emergency-check exposure: Palo Alto GlobalProtect (CVE-2026-0257), FortiOS (CVE-2022-40684), GitLab (CVE-2023-7028) — Operation Master is actively scanning for these at internet scale.
24 hours:
- All five pulses involve credential theft. If any endpoint hunt hits, treat all credentials stored in browsers on that host as compromised: force resets for domain accounts, revoke OAuth refresh tokens and active sessions (critical given Operation Master's OAuth device-code phishing), and invalidate web session cookies.
- Audit Chrome native messaging host registrations fleet-wide via the PowerShell script.
- Audit Tailscale installations against your approved software inventory — Kothamine hides C2 inside sanctioned-looking mesh VPN traffic.
- Review MFA fatigue / device-code grant logs in Entra ID for anomalous OAuth consent.
1 week:
- Patch or mitigate the full Operation Master CVE list; prioritize internet-facing appliances.
- Enforce application control (WDAC/AppLocker) blocking unsigned drivers and executables in user-writable paths; block double-extension files at email gateway and web proxy.
- Restrict browser credential storage risk: enable App-Bound Encryption where available, deploy EDR tamper protection for browser data paths, and move users to hardware-backed password managers.
- Add npm package vetting to developer workstations (lockfiles, private registry proxying, typosquat detection) to close the Kothamine supply-chain vector.
- Enhance DNS analytics for tunneling detection (query length/entropy/volume baselines) to counter AdaptixC2-style C2.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.