Soundbite is an unvalidated threat-actor label associated with a Windows intrusion cluster involving malicious document execution, PowerShell-based payload retrieval, unsigned loader execution, host and domain discovery, persistence via autorun configuration, additional payload staging, and attempted lateral movement using remote service queries and WMI. Observed behavior includes use of LOLBins such as PowerShell, rundll32, certutil, sc.exe, and wmic.exe; execution of discovery commands; transfer of follow-on tooling; and outbound web communications consistent with command-and-control or possible data transfer. The available evidence does not support reliable attribution to a known intrusion set, nation-state operator, or criminal group, and any overlap with names such as APT32, Phoreal, Fireant, or Metakit remains uncorroborated. Soundbite should therefore be treated as a provisional cluster name rather than a confidently established threat actor identity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.