Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

3d393f2bdb67d15602a96a1496a82942

TLP:CLEAR
Active

MD5 Hash

Description

An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.

Sightings (0)

No sightings recorded yet

Details

Name / Label
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
Pattern Type
STIX
Confidence
75%
Valid From
Aug 12, 2026 12:02
Total Sightings
0
Added
Aug 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 3d393f2bdb67d15602a96a1496a82942

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.