Brocoiner malware family
Brocoiner is a malware family tracked by MalwareAnalyzer by Cyble across 8 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-11.
Corpus statistics
- Publicly analyzed samples: 8
- First seen: 2026-08-05
- Last seen: 2026-08-11
- Verdicts: malicious 8
- File types: script 8
Extracted command-and-control infrastructure
- https://resources.blogblog.com/img/widgets/icon_contactform_cross.gif - 8 samples
- https://www.blogger.com - 8 samples
- https://www.blogger.com/static/v1/v-css/368954415-lightbox_bundle.css - 8 samples
- https://www.blogger.com/static/v1/jsbin/3018908849-lbx__pt_br.js - 3 samples
- https://www.blogger.com/rpc_relay.html - 2 samples
- https://www.blogger.com/static/v1/jsbin/3766621756-lbx__pt_br.js - 2 samples
- https://www.blogger.com/unvisited-link- - 2 samples
- http://2.bp.blogspot.com/-FDUk5p0Lp58/U-F1XUpV-0I/AAAAAAAAJBM/xd85R_OxyD8/s1600/jos%C3%A9+borges.png - 1 sample
- http://2.bp.blogspot.com/-FDUk5p0Lp58/U-F1XUpV-0I/AAAAAAAAJBM/xd85R_OxyD8/s72-c/jos%C3%A9+borges.png - 1 sample
- http://josier-organizedchaos.blogspot.com/ - 1 sample
- http://josier-organizedchaos.blogspot.com/favicon.ico - 1 sample
- http://josier-organizedchaos.blogspot.com/search - 1 sample
- http://jotaemeshon-policiaisassassinados.blogspot.com/ - 1 sample
- http://jotaemeshon-policiaisassassinados.blogspot.com/2013/ - 1 sample
- http://jotaemeshon-policiaisassassinados.blogspot.com/favicon.ico - 1 sample
- http://jotaemeshon-policiaisassassinados.blogspot.com/search - 1 sample
- http://jotamaria-8ze.blogspot.com/ - 1 sample
- http://jotamaria-8ze.blogspot.com/favicon.ico - 1 sample
- http://jotamaria-8ze.blogspot.com/search - 1 sample
- http://jotamaria-8ze.blogspot.com/search/label/STPM%20JOTA%20MARIA - 1 sample
Recent Brocoiner samples
- 66265f3a8fa4ef98de98874eb986fbed1518a2be4512d42b88a910378c08075e - malicious (2026-08-11)
- ee4c08d432c83f10f4e46cf0e4a06f963050277c693b31d94ee5da11b5cc59b6 - malicious (2026-08-10)
- 859edf65a16fd5c2e7e92ba7f78767505cd8168aa72f1ae456dcbf6463082678 - malicious (2026-08-09)
- b75d18678acb7fd515393ea1b91798eaeeb844002f2750a673e5f96fa6f503fe - malicious (2026-08-09)
- 6e2834533c6f5323b2f4efaa51ca97c735b6937d50363c0b4c0033ca12a4d29f - malicious (2026-08-08)
- 785afe28f8cebf5e3e0f74470b4012e8cfc0acf061504c5a4d20d8fe8dbf7862 - malicious (2026-08-07)
- 1575b5858b0a6d2a0f018ae8ff02cf021294ba208f6bac724f42c1124390b458 - malicious (2026-08-05)
- 91b2aa1a8a4c0d955c149f15986a4ce6805bcb6f3b5d0690e6819da0b42eb7d4 - malicious (2026-08-05)
Frequently asked about Brocoiner
- What is Brocoiner?
- Brocoiner is a malware family tracked by MalwareAnalyzer by Cyble across 8 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-11.
- How many Brocoiner samples have been analyzed?
- MalwareAnalyzer by Cyble holds 8 publicly analyzed samples attributed to Brocoiner, first seen 2026-08-05 and most recently 2026-08-11. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does Brocoiner use?
- Brocoiner samples in this corpus are distributed as script (8).
- Does Brocoiner use command-and-control infrastructure?
- Yes. 42 distinct command-and-control indicators have been extracted from Brocoiner samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Brocoiner malicious?
- 8 of 8 analyzed Brocoiner samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends