Threat Summary
Two active intrusion campaigns surfaced in today's OTX pulse feed, and while they differ in tooling and geography, they share a common operational signature: abuse of legitimate tooling to blend into enterprise noise.
Campaign 1 — Rogue ScreenConnect + XMRig (global, opportunistic): Multiple organizations report intrusions beginning with social engineering that results in unauthorized installation of ConnectWise ScreenConnect — a legitimate remote monitoring and management (RMM) tool. Once installed, the rogue client executes a chain of four sequential VBScript payloads (1.vbs through 4.vbs) that profile the host, enumerate installed security products, establish persistence, and stage additional tooling. Critically, the modified ScreenConnect client exhibits worm-like propagation behavior, spreading laterally across unrelated hosts without additional social engineering — meaning a single phished user can seed an environment-wide outbreak. The final-stage payload is XMRig, the ubiquitous Monero cryptocurrency miner, indicating a financially motivated actor monetizing compromised compute at scale.
Campaign 2 — SockTz + AI-Augmented Intrusions (CL-CRI-1131, Latin America): Unit 42-tracked activity targeting transportation organizations and government entities in Mexico and Ecuador, plus financial-sector victims in Brazil. Operators leverage living-off-the-land (LotL) techniques, a self-hosted NextChat instance (an open-source ChatGPT UI) to operationally integrate AI tooling into the intrusion lifecycle — likely for phishing content generation, scripting assistance, and victim reconnaissance — and deploy SockTz, a SOCKS5 proxy implant that converts compromised hosts into relay nodes for anonymized C2 and follow-on access. The C2 infrastructure leans heavily on free dynamic DNS (duckdns.org) subdomains themed to Mexican government services (repuve, vacunas, intel, geo, apodo), strongly suggesting Spanish-language phishing lures impersonating federal programs.
Collective read: Both campaigns exemplify the modern crimeware playbook — trusted binaries (ScreenConnect), free dynamic DNS, AI-assisted operations, and proxy-based C2 — engineered to defeat reputation-based detection. Objective set: resource hijacking (XMRig) and persistent proxy footholds for resale or downstream intrusion (SockTz).
Threat Actor / Malware Profile
Rogue ScreenConnect / XMRig Loader Chain
- Distribution: Social engineering (phishing/callback-style lures) prompting victims to install a trojanized or attacker-registered ScreenConnect client.
- Payload behavior: Four-stage VBScript execution (
1.vbs→4.vbsviawscript.exe/cscript.exe): Stage 1 profiles the system (OS, domain, hardware), Stage 2 enumerates AV/EDR products (WMIroot\SecurityCenter2queries), Stage 3 installs persistence, Stage 4 downloads and executes XMRig and auxiliary tools. - C2 communication: ScreenConnect relay traffic plus direct miner callbacks; observed infrastructure includes
http://homehub.opik.net:443and dynamic-DNS hostborertors92.anondns.net. XMRig speaks Stratum mining protocol to pool endpoints. - Persistence: ScreenConnect installs as a Windows service (
ScreenConnect Client (*)service naming), supplemented by script-based persistence (Run keys/scheduled tasks typical of this chain). - Anti-analysis: Security-product enumeration before payload deployment; legitimate signed RMM binary defeats hash-based blocklisting; worm-like spread via the RMM's own remote-execution capability leaves minimal malware on disk.
SockTz (CL-CRI-1131)
- Distribution: Phishing campaigns using Mexico/Ecuador government-themed lures (vehicle registry
REPUVE, vaccination programs, intelligence/geospatial themes) aimed at transportation, government, and finance sectors. - Payload behavior: SockTz establishes a SOCKS5 proxy on the victim host, tunneling attacker traffic through the compromised machine — converting the endpoint into both a persistence point and an anonymity layer for further operations.
- C2 communication: Dynamic DNS hostnames under
*.duckdns.org(m-doxa-repuve,m-doxa-vacunas,m-doxa-intel,m-doxa-geo,m-doxa-apodo) resolving to rotating infrastructure; proxy traffic masquerades as ordinary outbound TLS. - Persistence: Service installation and LotL mechanisms (scheduled tasks, WMI) consistent with the campaign's LotL-heavy tradecraft.
- Anti-analysis: Living-off-the-land execution chains, self-hosted NextChat AI tooling for operational support (reducing attributable infrastructure), and DDNS churn to evade static blocklists.
IOC Analysis
The indicator set decomposes into three operational buckets:
- FileHash-SHA256 (11 total): Hash indicators for the VBScript loader stages, modified ScreenConnect binaries, XMRig payloads, and SockTz implants. These are highest-fidelity for retro-hunting in EDR telemetry and email/web gateway logs, but expect short shelf life — VBScript stages are trivially re-obfuscated. Operationalize by pushing to EDR blocklists and querying historical process/file events, not just forward-blocking.
- Dynamic DNS hostnames (5):
*.duckdns.org(SockTz) and*.anondns.net(ScreenConnect chain). DDNS domains rotate IPs frequently — block at the DNS resolver/sinkhole layer, not just the firewall, and alert on any resolution of the parent patterns (duckdns.orgsubdomains matchingm-doxa-*, anyanondns.netresolution in environments with no legitimate use). - URL (1):
http://homehub.opik.net:443— C2/payload staging over non-standard port-to-scheme pairing (HTTP on 443), a detection opportunity in itself. Proxy and NGFW logs should flag protocol/port mismatches.
Tooling: Normalize indicators into STIX/TAXII for SIEM ingestion (MISP, OpenCTI); use shodan/censys for live resolution of DDNS hosts to catch IP drift; validate hashes against VirusTotal/MalwareBazaar before blocking to avoid false positives on legitimate ScreenConnect builds.
Detection Engineering
---
title: Rogue ScreenConnect Installation or Worm-Like RMM Execution
id: 9f2a1c3e-7b4d-4e5a-a1f2-sc01nn3ct001
status: experimental
description: Detects installation or execution of ScreenConnect RMM clients from non-standard paths or with suspicious naming, consistent with rogue ScreenConnect intrusions delivering XMRig via VBScript staging.
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|contains: 'ScreenConnect'
selection_path:
Image|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\Users\Public\'
- '\ProgramData\'
selection_child:
ParentImage|contains:
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
condition: selection_img and (selection_path or selection_child)
falsepositives:
- Legitimate managed ScreenConnect deployments (whitelist known IT paths)
level: high
tags:
- attack.execution
- attack.command_and_control
- attack.t1219
- attack.t1059.005
date: 2026/10/03
---
title: VBScript Security Product Enumeration and Staging Chain
id: 8e1b2d4f-6c3a-4d2b-b9e1-vb5cr1pt0002
status: experimental
description: Detects sequential VBScript execution patterns (numbered .vbs payloads) and WMI-based AV enumeration consistent with the 1.vbs-4.vbs staging chain observed in rogue ScreenConnect/XMRig intrusions.
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: windows
detection:
selection_proc:
Image|endswith:
- '\wscript.exe'
- '\cscript.exe'
selection_scriptname:
CommandLine|contains:
- '1.vbs'
- '2.vbs'
- '3.vbs'
- '4.vbs'
selection_avenum:
CommandLine|contains:
- 'AntiVirusProduct'
- 'root\\SecurityCenter2'
- 'Win32_ComputerSystem'
condition: selection_proc and 1 of selection_*
falsepositives:
- Legitimate administrative VBScript (rare in modern environments)
level: high
tags:
- attack.execution
- attack.discovery
- attack.t1059.005
- attack.t1518.001
date: 2026/10/03
---
title: SockTz C2 Dynamic DNS Resolution or XMRig Mining Callback
id: 7d0c3e5a-5f2b-4c1a-c8d2-s0cktz000003
status: experimental
description: Detects DNS resolution or network connections to known SockTz C2 duckdns subdomains, anondns.net ScreenConnect C2, and the opik.net staging URL observed in current OTX pulses.
author: Security Arsenal Threat Intelligence
logsource:
category: dns
product: windows
detection:
selection:
QueryName|contains:
- 'm-doxa-apodo.duckdns.org'
- 'm-doxa-geo.duckdns.org'
- 'm-doxa-intel.duckdns.org'
- 'm-doxa-vacunas.duckdns.org'
- 'm-doxa-repuve.duckdns.org'
- 'borertors92.anondns.net'
- 'homehub.opik.net'
condition: selection
falsepositives:
- None expected; all listed hosts are confirmed malicious infrastructure
level: critical
tags:
- attack.command_and_control
- attack.t1071.001
- attack.t1568.002
- attack.t1090
date: 2026/10/03
// Security Arsenal — Rogue ScreenConnect / XMRig + SockTz Hunt (Sentinel)
// Part 1: Network indicators from OTX pulses
let maliciousHosts = dynamic(["m-doxa-apodo.duckdns.org","m-doxa-geo.duckdns.org","m-doxa-intel.duckdns.org","m-doxa-vacunas.duckdns.org","m-doxa-repuve.duckdns.org","borertors92.anondns.net","homehub.opik.net"]);
let netHits = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (maliciousHosts)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort
| extend Hunt = "IOC-Network";
// Part 2: VBScript staging + ScreenConnect execution behavior
let procHits = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where (FileName in~ ("wscript.exe","cscript.exe") and ProcessCommandLine has_any ("1.vbs","2.vbs","3.vbs","4.vbs","AntiVirusProduct","SecurityCenter2"))
or (FileName has "ScreenConnect" and (FolderPath has_any ("\\Temp\\","\\Public\\","\\Roaming\\","\\ProgramData\\")))
or (InitiatingProcessFileName has "ScreenConnect" and FileName in~ ("powershell.exe","cmd.exe","wscript.exe","cscript.exe","bitsadmin.exe","certutil.exe"))
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, FolderPath, InitiatingProcessFileName, SHA256
| extend Hunt = "Behavior-Execution";
// Part 3: File hash retro-hunt for OTX SHA256 indicators
let iocHashes = dynamic(["08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020","110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66","19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260","de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457","de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede","ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de","7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8","4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5","46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c"]);
let hashHits = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where SHA256 has_any (iocHashes)
| project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, ProcessCommandLine
| extend Hunt = "IOC-Hash";
union netHits, procHits, hashHits
| sort by TimeGenerated desc
# Security Arsenal — Rogue ScreenConnect / XMRig / SockTz Host Hunt
# Run elevated on suspect endpoints or deploy fleet-wide via GPO/Intune/EDR
$Report = @()
# 1. Rogue ScreenConnect services (legit installs have known, documented names)
$scServices = Get-CimInstance Win32_Service | Where-Object { $_.Name -match 'ScreenConnect' -or $_.DisplayName -match 'ScreenConnect' }
foreach ($s in $scServices) {
$suspicious = $s.PathName -match 'Temp|Public|Roaming|ProgramData(?!\\ScreenConnect)'
$Report += [PSCustomObject]@{Check='ScreenConnect Service'; Finding="$($s.Name) | $($s.PathName) | State=$($s.State)"; Suspicious=$suspicious}
}
# 2. Numbered VBScript staging files in common drop locations
$vbsPaths = @("$env:TEMP","$env:PUBLIC","$env:APPDATA","$env:LOCALAPPDATA","C:\ProgramData")
foreach ($p in $vbsPaths) {
Get-ChildItem -Path $p -Recurse -ErrorAction SilentlyContinue -Include '1.vbs','2.vbs','3.vbs','4.vbs' |
ForEach-Object { $Report += [PSCustomObject]@{Check='VBScript Stager'; Finding=$_.FullName; Suspicious=$true} }
}
# 3. Run-key persistence referencing scripts or RMM tooling
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run')
foreach ($k in $runKeys) {
if (Test-Path $k) {
(Get-ItemProperty $k).PSObject.Properties | Where-Object { $_.Value -match 'vbs|ScreenConnect|xmrig|duckdns|anondns' } |
ForEach-Object { $Report += [PSCustomObject]@{Check='Run Key Persistence'; Finding="$k :: $($_.Name) = $($_.Value)"; Suspicious=$true} }
}
}
# 4. Scheduled tasks launching scripts/miners
Get-ScheduledTask | Where-Object { ($_.Actions.Execute -match 'wscript|cscript|powershell') -and ($_.Actions.Arguments -match 'vbs|xmrig|duckdns|anondns|http') } |
ForEach-Object { $Report += [PSCustomObject]@{Check='Scheduled Task'; Finding="$($_.TaskName) -> $($_.Actions.Execute) $($_.Actions.Arguments)"; Suspicious=$true} }
# 5. Active connections to known C2 infrastructure
$c2Patterns = 'duckdns\.org|anondns\.net|opik\.net'
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | ForEach-Object {
try {
$dns = (Resolve-DnsName $_.RemoteAddress -ErrorAction Stop).NameHost
if ($dns -match $c2Patterns) {
$Report += [PSCustomObject]@{Check='C2 Connection'; Finding="PID $($_.OwningProcess) -> $($_.RemoteAddress):$($_.RemotePort) [$dns]"; Suspicious=$true}
}
} catch {}
}
# 6. XMRig artifacts (miner binary, config, high-CPU unknown processes)
Get-ChildItem -Path 'C:\' -Recurse -Depth 4 -ErrorAction SilentlyContinue -Include 'xmrig*.exe','config.json' |
Where-Object { $_.FullName -match 'xmrig' } |
ForEach-Object { $Report += [PSCustomObject]@{Check='XMRig Artifact'; Finding=$_.FullName; Suspicious=$true} }
$Report | Where-Object { $_.Suspicious } | Format-Table -AutoSize
if (-not ($Report | Where-Object { $_.Suspicious })) { Write-Host '[+] No indicators of compromise found.' -ForegroundColor Green }
Response Priorities
Immediate (0–4 hours):
- Block all five
m-doxa-*.duckdns.orghostnames,borertors92.anondns.net, andhomehub.opik.netat DNS resolver, proxy, and EDR network layers; push the 11 SHA256 hashes to EDR blocklists and email/web gateway retro-search. - Inventory every ScreenConnect (and other RMM — AnyDesk, TeamViewer, Splashtop) installation in the environment; treat any instance outside IT's managed deployment as an incident. The worm-like propagation means one rogue client likely implies multiple compromised hosts.
- Isolate any host with confirmed C2 resolution or IOC hash execution; capture memory before remediation to recover miner configuration and staged payloads.
24 hours:
- While neither campaign is primarily credential-theft focused, SockTz proxy access and RMM footholds enable interactive intrusion — force credential resets for any user on a confirmed-compromised host, and audit for newly created local/domain accounts and unauthorized admin group additions.
- Review authentication logs for anomalous remote sessions correlating with ScreenConnect install timestamps; hunt for lateral movement (SMB/WinRM/RDP) originating from infected hosts during the dwell window.
- For LATAM-region business units: escalate phishing-awareness alerting on government-themed lures (REPUVE, vaccination, geospatial programs) in Spanish-language email flows.
1 week:
- Implement an RMM allowlist policy: block execution of unapproved remote access tools via application control (WDAC/AppLocker) — this single control breaks the ScreenConnect campaign's core mechanism.
- Deploy DNS-layer categorization blocking or alerting on free dynamic-DNS TLDs (
duckdns.org,anondns.net,no-ip.*) absent documented business need. - Constrain VBScript: disable
wscript/cscriptvia attack surface reduction rules for users without a business justification, and enable AMSI script content logging. - Add egress controls for Stratum mining protocol and non-browser traffic on port 443 failing TLS inspection, closing both the XMRig monetization path and SockTz-style proxy tunnels.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.