Three distinct payload variants exfiltrating through DoH tunnels. Signature drift <0.4% from CozyBear baseline. Recommend immediate IOC distribution to T1+T2 clients.
Russian-language forum BLACKHOLE.SX posting fragmentary PoC. Cross-corroborated via TG channel @gh0st_proto. Patch posture: none upstream.
Attack origin: bulletproof ASN 47890 (NL). Dictionary suggests insider list — 71% hit rate on rotated creds <30 days old.
Postinstall script pulls stage-2 from kasvik[.]xyz. ~14k weekly downloads. Maintainer account confirmed compromised via session-token theft.