SIMPOBOXSPY is a bespoke data-exfiltration tool used by the Earth Kurma cyberespionage group. It uploads password-protected RAR archives containing collected victim data to Dropbox using an access token. Earth Kurma used SIMPOBOXSPY alongside document-collection and staging tooling in intrusions targeting government and telecommunications organizations in Southeast Asia, including organizations in the Philippines, Vietnam, Thailand, and Malaysia. Tooling overlaps have been identified with activity associated with ToddyCat, but this does not establish a conclusive attribution between the groups.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Two customised tools handle the exfiltration - SIMPOBOXSPY for Dropbox and ODRIZ for OneDrive.
...siphon sensitive data using tools like TESDAT and SIMPOBOXSPY... One of the bespoke tools used for data exfiltration is SIMPOBOXSPY, which can upload the RAR archive to Dropbox with a specific access token.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Component leveraging Dropbox for stealthier data exfiltration.
Tool used for exfiltrating stolen documents to public cloud storage services such as Dropbox and OneDrive.
Custom espionage tool associated with credential theft and data exfiltration; linked in reporting to tooling overlaps with ToddyCat (not conclusive attribution).
Bespoke data-exfiltration malware that uploads staged RAR archives to Dropbox using an access token; noted to share overlaps with tooling associated with ToddyCat (attribution not definitive).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.