APOPHiS is a threat actor associated with malware intrusion campaigns that use social engineering, trojanized software, spearphishing attachments, and abused software update channels to compromise Windows systems. The actor has been linked to operations involving clipboard-delivered PowerShell execution and the deployment of ValleyRAT_S2, a second-stage ValleyRAT backdoor used for long-term covert access and theft of sensitive information. Observed tradecraft includes initial access through fake productivity tools and cracked or trojanized installers, as well as user-executed PowerShell commands copied to the clipboard under false pretenses. APOPHIS has used obfuscated PowerShell to decode and execute payloads in memory, clear DNS cache entries, manipulate the clipboard, and present decoy success messages to reduce suspicion. Persistence mechanisms include scheduled jobs, Windows Task Scheduler abuse via COM APIs, staged files in temporary and application-data locations, watchdog scripts that restart malware when terminated, and in some cases registry-based startup persistence. The actor’s malware capabilities include remote code execution, system discovery, process and file-system enumeration, registry inspection, credential theft, keylogging, file upload and download, payload injection, and exfiltration of stolen data to command-and-control infrastructure. ValleyRAT_S2 has been described as a C++ remote access trojan using a custom TCP protocol for command and control and is suited to harvesting online banking credentials, payment data, and internal financial documents. Additional observed payloads include information-stealing malware that extracts browser credentials, cookies, autofill data, tokens, extension data, and cryptocurrency wallet-related artifacts from a broad range of Chromium- and Mozilla-based applications, while also collecting host information through WMI and employing anti-analysis checks. The actor’s targeting, as directly supported, is oriented toward financial information theft rather than disruptive or destructive effects. Known aliases directly supported here are limited to APOPHIS and apophis.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APOPHiS is tracking and attributing the ValleyRAT_S2 campaign, which uses a sophisticated remote access trojan to steal financial data and maintain persistent access in targeted organizations.
A stealer-focused malware activity cluster delivering a malicious PowerShell loader that establishes persistence, retrieves additional payloads, and deploys a Windows executable that harvests browser credentials, cookies, autofill data, tokens, crypto-wallet extensions, and system information, then exfiltrates the data to attacker-controlled infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.