Microcin is a Trojan associated with the Chinese-speaking threat cluster SixLittleMonkeys and has been observed in espionage-oriented intrusion activity. Reporting links a newer version of Microcin to active campaigns in which it was used alongside the HawkEye RAT as a later-stage implant. Microcin has also been noted in environments compromised by actors associated with APT41, although at least some of that linkage is assessed only with low confidence.
A notable characteristic associated with Microcin is the use of steganography. It has been cited among malware families that conceal payloads or configuration data inside image files, including BMP containers, to obscure malicious content and blend delivery or staging traffic with benign-looking media. Public tooling references indicate analysts have parsed both Microcin configuration data and steganographic BMP content, supporting the assessment that image-based hidden data is part of its tradecraft.
Available information supports classifying Microcin as a Trojan used in multi-stage intrusion chains rather than as a commodity malware family. It appears in post-compromise contexts and is associated with covert payload staging and defense-evasion techniques intended to reduce visibility of malicious artifacts and communications. Public reporting in the supplied material does not establish a definitive initial infection vector, victimology profile, or full capability set beyond its role as a staged implant using steganographic concealment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Семейство вредоносного ПО, упомянутое как использующее стеганографию для сокрытия данных или коммуникаций.
Additional implant observed in the same environment with timeline overlap suggesting a low-confidence relationship/shared resources with the MoonBounce/ScrambleCross activity; noted similarity in scheduling logic between Microcin and MoonBounce’s user-mode stager.
Trojan used in espionage campaigns, often as an initial stage loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.