VDB
GCVE-110-OSM-2026-11953
GCVE-110-OSM-2026-11953
Advisory PublishedCVSS 8.8/10
Hosts BifrostWallet.exe, a trojanized crypto wallet installer that silently installs a ScreenConnect RMM client configured to phone home to bbdots.com:8041 (ScreenConnect instance ID 6d833e57e5a31c6a) as a Guest session, giving the operator full remote access. Published by the same GitHub account (tesssmax, id 301410327) that later ran a much larger 46-repo campaign using a DIFFERENT ScreenConnect C2 (www.somtinn.com, instance 008c4a1933454b9c, disguised as "Feedback Tool") starting 12 days after this repo. Different C2 domain, different ScreenConnect instance ID, and no "Feedback Tool" disguise branding found in this sample, so it is tracked as a separate/earlier operation rather than folded into that campaign's IOC set.
Malicious payload found in: GitHub Release asset "BifrostWallet.exe" (sha256:f8cd736a531c65cce00a01fab875cb2cc350b4561e6eaa643fb46d1b62cb3ba7)
NSIS-packed Electron installer unpacks to a ScreenConnect MSI configured with:
?e=Access&y=Guest&h=bbdots.com&p=8041&k=<RSA key material>
ScreenConnect instance ID: 6d833e57e5a31c6a
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
506 records in the GCVE database · Updated September 11, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.