d3f@ck is a malware delivery and intrusion activity cluster associated with the GhostWeaver fileless PowerShell remote access trojan and linked to the broader TAG-124 traffic distribution ecosystem. The actor has been observed operating downstream of web-based initial access chains in which compromised websites and fake browser update lures are used to deliver staging malware, after which victim profiling determines whether a full intrusion payload is deployed. d3f@ck has been associated with GhostWeaver delivery through MintsLoader-based filtering that attempts to distinguish real user systems from sandbox and analysis environments, improving operational security and reducing exposure to defenders. GhostWeaver is a memory-resident PowerShell RAT that uses raw TCP wrapped in TLS and a custom compressed JSON protocol rather than conventional HTTP-based command and control. The malware supports long-term beaconing, modular tasking, and reflective loading of .NET plugins without writing those modules to disk. Documented plugin capabilities include browser credential theft, form grabbing and web injection, Outlook data theft, and cryptocurrency wallet theft. The framework also supports redeployment of additional loaders, enabling continued post-compromise flexibility. The intrusion set demonstrates mature defense-evasion and persistence tradecraft. Observed behaviors include AMSI bypass in staging malware, environment scoring based on virtualization and hardware characteristics, antivirus-aware execution paths, scheduled-task persistence, disabling of Task Scheduler operational logging, and a UAC bypass using CMSTPLUA with process-environment masquerading. The malware family has also used multiple domain generation algorithm schemes across the kill chain, indicating an effort to complicate infrastructure tracking and resilience. Aliases and related tracking include overlap with activity tracked as TA582 and UNC4108 in connection with GhostWeaver operations. The actor appears primarily focused on malware delivery, persistence, credential and data theft, and broader post-exploitation rather than ransomware or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.