DarkVishnya is a threat actor tracked in the provided content as DarkVishnya. The content attributes to this actor use of PowerShell for execution, including creating shellcode loaders; creation of new Windows services for shellcode loader distribution and persistence; use of remote access tooling including DameWare Mini Remote Control for lateral movement; use of tools such as Impacket, Winexe, and PsExec; port scanning and active service enumeration for network discovery; and network share discovery. The ATT&CK techniques explicitly associated in the content include T1059.001 (PowerShell), T1543.003 (Windows Service), T1068 (Exploitation for Privilege Escalation), T1053 (Scheduled Task/Job), T1219 (Remote Access Tools), T1129 (Shared Modules), and T1135 (Network Share Discovery).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor for exploitation activity related to abuse of the Windows Cloud Files API / cldapi.dll detection.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed as a threat actor associated with exploitation and privilege-escalation detection coverage for Windows admin password changes by non-admin users.
Listed as a threat actor associated with exploitation for privilege escalation and Windows service persistence/installation in the detection annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.