Habr•August 29, 2026•🇷🇺Translated from Russian

Backblaze Responds in Minutes While reg.ru Delays Action on Banking Trojan Infrastructure

A researcher who encountered spam messages promoting a fake VPN application in Telegram chats spent a week analyzing the resulting Android Trojan and documenting how different hosting providers responded to abuse reports.

The malware begins as a heavily obfuscated dropper that requests accessibility services, then installs a second-stage payload retrieved from an S3 bucket hosted on Backblaze. Once active, the Trojan disables network access for security applications including Kaspersky products, Samsung security services, and Google Play Services by routing their traffic through a short-lived VPN tunnel.

Capabilities extracted from the decrypted payload include interception of banking SMS codes, real-time screen streaming via MediaProjection, keylogging, remote camera and microphone access, contact and file theft, and the ability to grant itself additional permissions through accessibility services. The sample also contains routines to hide from the app drawer and resist uninstallation.

Command-and-control traffic is directed to four domains registered through reg.ru. WHOIS records show the domains were created in August 2026 with a two-year registration term and point to a VPS used for data exfiltration. The researcher notified Backblaze, reg.ru, Kaspersky, and Russian CERT channels shortly after discovering the infrastructure.

Backblaze terminated the implicated account within eleven minutes of the report. In contrast, reg.ru replied after nearly a week, stating that it would act only upon a court decision or an official request from an authorized body. No visible action was taken by the Russian registrar or CERT during the observation period, allowing the operators to continue rotating payloads to new buckets and servers.

Related articles

Securitylab•Malware & Botnets

How Malware Evades Sandboxes: Detection Techniques and Defense Strategies

Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.

BoletimSec•Malware & Botnets

Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers

Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.

BoletimSec•Malware & Botnets

Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware

Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.

AntiMalware•Malware & Botnets

SC Malware on WordPress Restores Deleted Backdoors in Seconds via Eight Persistence Points

Researchers at Sucuri have analyzed the SC malware targeting WordPress sites, which rapidly restores any removed backdoor components through a minimum of eight interconnected persistence mechanisms. The infection hides across PHP configuration settings, hidden loaders, theme files, and plugins, with some elements executing before standard WordPress plugins load. Copies of the malicious code are also stored in the database and System V shared memory on supported servers, allowing full reinfection from surviving sources after file cleanup. The backdoor evades plugin listings, gathers site and administrator session data, deploys additional PHP code, and disables security plugins while injecting JavaScript for payment data theft in online stores. Command-and-control occurs through public Ethereum RPC gateways and smart contracts with multiple fallback channels. Sucuri warns that PHP caching of the loader directive can crash request handling if the referenced file is deleted without prior preparation, and recommends a sequenced cleanup process.