CNB Bot is a previously undocumented .NET implant and loader used by the financially motivated REF1695 operation against Windows systems. It is distributed through counterfeit software installers, including ISO-based lures that socially engineer victims into bypassing Microsoft SmartScreen. A preceding loader can weaken Microsoft Defender protections before installing CNB Bot and presenting a decoy application error.
CNB Bot polls command-and-control infrastructure over HTTP POST with encrypted request values and authenticates received operator tasks using RSA-2048 RSA-SHA256 signatures. It supports downloading and executing additional payloads, self-updating, and uninstalling itself with cleanup actions, making it a modular staging component for follow-on malware. It establishes high-privilege scheduled-task persistence and performs virtual-machine and analysis-environment checks based on host, firmware, process, registry, and network-adapter characteristics. REF1695 has used CNB Bot alongside remote-access malware and cryptocurrency-mining payloads as part of campaigns monetized through cryptomining and CPA fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CNB Bot is a previously undocumented .NET implant with RSA-2048 signed task authentication.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Campaign 2 registers a scheduled task named SVCConfig with an ONLOGON trigger and HIGHEST privilege; CNB Bot creates HostDataProcess to run every 10 minutes.
By decrypting traffic captured in VirusTotal sandboxes, we observed that the C2 server at windirautoupdates[.]top was automatically issuing a download-and-execute task directing the implant to fetch an XMR mining payload from https://github[.]com/.../MnrsInstllr_240126[.]exe.
The loader invokes PowerShell with -WindowStyle Hidden to register Defender exclusions, execute extracted stages, and launch payloads.
...a fake ISO file that distributed a .NET Reactor-protected loader... REF1695 also leveraged ISO lures to spread... a custom .NET-based XMRig loader...
...distributed a .NET Reactor-protected loader...
The scam usually starts with a fake download, often an ISO file. To dodge security checks, the hackers include a ReadMe.txt file that uses social engineering. It claims the software is from a small non-profit team of developers that can’t afford official Windows certificates and is providing the software for free.
Stage 2 writes a temporary .bat file that forcefully deletes the installer binary; CNB Bot self-deletes the original copy via a self-deleting BAT script.
...distributed a .NET Reactor-protected loader...
The encrypted next-stage module is stored as a .NET resource and decrypted via Triple DES (3DES) in CBC mode using an embedded key and IV. The decrypted output is a GZip-compressed PE.
Execute: .exe (hidden), .bat/.cmd (cmd /c), .vbs (wscript.exe), other (ShellExecute).
Writes a VBScript wrapper sysdata.vbs alongside the binary: CreateObject("WScript.Shell").Run """<installed_path>""", 0, False. Creates a scheduled task named HostDataProcess via schtasks.exe, configured to run wscript.exe //nologo sysdata.vbs every 10 minutes at HIGHEST privilege
At startup, CNB Bot uses five different methods to check for VM detection...
CNB Bot checks WMI manufacturer/model and BIOS data, VM-related processes, registry keys, and virtual-machine MAC prefixes.
CNB Bot sends local IPv4 information and retrieves the external IP via ipify[.]org, icanhazip[.]com, or ident[.]me.
Fields sent on every request: desktop machine name, username username, os Windows version... privileges user OR admin... client_path full path of running executable... external IP via ipify[.]org / icanhazip[.]com / ident[.]me
On each tick, IsAnalysisToolRunning() compares all running process names against a hardcoded list of 35 security and monitoring tools (Taskmgr, ProcessHacker, Wireshark, Procmon, etc.).
CNB Bot profiles the victim and sends Windows version, privileges, processor name, GPU names, and executable path to its C2.
At startup, CNB Bot uses five different methods to check for VM detection...
It communicates with a command-and-control (C2) server using HTTP POST requests.
CNB Bot communicates with C2 by HTTP POST requests; PureRAT uses configured web C2 servers to receive encrypted Protobuf command messages.
PureRAT received a download-and-execute task directing it to fetch an XMR mining payload from a raw GitHub URL; CNB Bot supports download_execute.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of the malicious toolkit delivered through fake software installers; used to give the attackers persistent control and the ability to update malicious code.
An implant used to provide remote access and enable additional payload injection on compromised systems.
A previously undocumented .NET implant that functions as a loader, capable of downloading and executing additional payloads, updating itself, uninstalling itself, performing cleanup actions, and communicating with a C2 server over HTTP POST requests.
A previously undocumented .NET implant with integrated loader capabilities. It establishes persistence via scheduled tasks, performs VM checks, polls C2 servers for commands, and supports download-and-execute, self-update, and uninstall/cleanup. It uses AES-256-CBC for communications and RSA-SHA256 signature verification for task authentication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.