Get2 is a Windows downloader associated with the financially motivated threat actor TA505, also tracked as GOLD TAHOE and sometimes linked operationally with FIN11 reporting. It emerged in TA505 phishing operations in 2019 and has been used as an intermediate payload to retrieve and launch additional malware, including FlawedGrace, FlawedAmmyy, SDBbot, and in some campaigns tooling that preceded CL0P ransomware deployment. Get2 has also been cited as a loader lineage or close analogue in later TA505-style email-to-document-to-installer intrusion chains.
Get2 is typically delivered through phishing campaigns using malicious Excel attachments, including macro-enabled or embedded-object documents, and in some cases via links to landing pages that serve the malicious spreadsheet. Once executed, the infection chain extracts and loads the Get2 component, which is written in C++ and has been observed exposed through varying DLL export names. On infected hosts, Get2 performs basic host reconnaissance by collecting the computer name, current username, Windows version, and a list of running processes. It communicates this information to hardcoded command-and-control infrastructure over HTTP and parses server responses to obtain follow-on payload locations and optional execution parameters.
Operationally, Get2 functions as a staging component for post-compromise malware deployment. It can execute retrieved binaries with command-line arguments and later variants added support for injecting DLL payloads into processes. ATT&CK-aligned reporting also associates it with process discovery, system owner or user discovery, web-protocol command and control, and DLL injection. Some observed campaigns indicate that Get2-triggered follow-on activity established persistence through secondary malware such as SDBbot, while certain related loader chains resembling Get2 or GetandGo also used installer stages that could add Run-key persistence.
Get2 has been used heavily in broad TA505 malspam operations targeting financial institutions and other sectors across North America, Europe, the Middle East, and elsewhere. It has also appeared in a long-dwell intrusion affecting a UK water utility, where a phishing email led to installation of Get2 and SDBbot before later hands-on-keyboard activity and data theft. Overall, Get2 is best understood as a TA505-associated downloader and execution utility designed to profile victims, contact web-based command infrastructure, and deliver subsequent access or monetization payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the Email -> XLS -> MSI (KiXtart/REBOL loader) chain, whose MSI closely resembles TA505’s Get2 / GetandGo loader
16 distinct techniques documented for this family, organized by ATT&CK tactic.
South Staffordshire’s investigation found that initial access occurred on 11 September 2020 through a successful phishing campaign. The opening of the malicious attachment to a phishing email led to the installation of the tool Get2 and the Remote Access Trojan, SDBBOT...
APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The POST data contains the following URL-encoded parameters: D - Computer name U - Username OS - Windows version PR - Pipe-delimited process list
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The downloader collects basic system information and sends it via an HTTP POST request to a hardcoded command and control (C&C) server.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TA505-associated loader referenced for similarity to the MSI component used in the MirrorBlast infection chain.
A new C++ downloader used as the initial payload in TA505 email campaigns. It collects basic system information, sends it via HTTP POST to a hardcoded C2, parses pipe-delimited responses, and downloads secondary payloads including FlawedGrace, FlawedAmmyy, Snatch, and SDBbot. Later versions added support for DLL injection/loading via RD86.
Backdoor malware capable of launching executables with supplied command-line arguments.
Malware capable of running executables with supplied command-line arguments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.