Reductor is a Windows malware family with remote-access Trojan functionality that is notable for covert manipulation of TLS-related randomness and certificate material on infected hosts. It was observed in 2019 and shows strong code similarities to COMpfun, with development assessed as likely originating from the same authors. Based on code similarities and victimology, Reductor has been tentatively associated with Turla. Known targeting included victims in Russia and Belarus.
Reductor supports core backdoor operations including uploading, downloading, deleting, and executing files, and it communicates with command-and-control infrastructure over HTTP POST using encrypted host identifiers. It can install root certificates embedded in its data section and can also receive additional certificates remotely. For persistence, it uses an LSA notification package.
Its most distinctive capability is host-side manipulation of TLS traffic without directly modifying packets on the wire. Reductor patches PRNG-related functions in browser and Windows cryptographic components in memory, including functions used by Firefox, Chrome, and Windows cryptographic APIs, in order to alter TLS client random values during handshakes. This allows it to embed encrypted victim-specific identifiers derived from certificate data and hardware characteristics into outbound TLS traffic. The malware therefore enables reliable victim marking and traffic correlation, and its certificate handling strongly suggests support for interception-oriented workflows, although analyzed samples did not themselves implement a full man-in-the-middle capability.
Observed delivery included trojanized software installers distributed through HTTP downloads, including software sought from warez ecosystems, as well as secondary deployment from systems already infected with COMpfun. In at least some cases, operators were assessed to have replaced legitimate installers in transit, indicating control over the victim’s network path during delivery. Reductor was deployed in both 32-bit and 64-bit forms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We called these new modules ‘Reductor’ after a .pdb path left in some samples. Besides typical RAT functions such as uploading, downloading and executing files, Reductor’s authors put a lot of effort into manipulating digital certificates and marking outbound TLS traffic with unique host-related identifiers.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A COMpfun successor mentioned as prior related malware that infected files on the fly to compromise TLS traffic.
A Trojan/RAT family that installs digital certificates, patches browser and system PRNG functions in memory to embed victim-specific identifiers into TLS client random values, communicates with C2 over HTTP POST, and supports file upload/download, execution, certificate renewal, and cleanup. It was distributed via trojanized installers and via COMpfun as a downloader.
COMpfun-related malware that infects files on-the-fly to enable compromise of TLS traffic.
Remote access trojan with advanced capabilities to manipulate digital root certificates and mark outbound TLS traffic with unique identifiers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.