KNOTWEED is a private-sector offensive actor associated with the Austrian surveillance-vendor DSIRF and its Subzero spyware toolset. The group conducted highly targeted operations against legal, financial, and non-governmental-organization victims in Europe and Central America. It used zero-day vulnerabilities in Adobe Reader and Microsoft Windows to obtain initial access and deployed Subzero following exploitation. Microsoft attributed active exploitation of the Windows local privilege-escalation vulnerability CVE-2022-22047 to KNOTWEED. Subzero includes the Jumplump persistence component and the Corelump primary payload, and supports credential collection, host and system-location discovery, internal reconnaissance, and remote access. KNOTWEED is also referred to as Denim Tsunami in reporting on CVE-2022-22047 exploitation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as actively exploiting Windows local privilege escalation via Activation Context Cache Poisoning (CSRSS-related) in-the-wild, specifically tied in the text to exploitation of CVE-2022-22047 for elevation of privilege to SYSTEM.
Associated with in-the-wild exploitation of Windows local privilege escalation via CSRSS activation context cache poisoning (CVE-2022-22047), using crafted activation context creation requests and malicious manifests to redirect DLL loading in privileged processes.
A DSIRF-produced private-sector offensive activity group conducting targeted espionage against legal, financial, and NGO victims in Europe and Latin America. It uses Adobe Reader and Windows zero-day exploits to deploy Subzero spyware and collect credentials, location data, and internal reconnaissance.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.