Stom Exfiltrator is an exfiltration tool used by the Mysterious Elephant APT. It is described as a commonly used exfiltration module, with a latest variant specifically designed to target files shared through the WhatsApp application. Reporting states that Mysterious Elephant used Stom Exfiltrator, alongside Uplo Exfiltrator, to capture and exfiltrate WhatsApp communications and files from compromised hosts, including documents, pictures, and archive files exchanged via WhatsApp Desktop. The malware has been observed in campaigns attributed to Mysterious Elephant targeting government and foreign affairs entities in the Asia-Pacific region, especially South Asia, including Pakistan, Bangladesh, Afghanistan, Nepal, and Sri Lanka. The broader intrusion set used spear-phishing, exploit kits, and malicious documents for initial access, followed by PowerShell-based staging and persistence, with additional tooling such as BabShell and MemLoader. High-confidence indicators specific to Stom Exfiltrator are not provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stom Exfiltrator is a module for exfiltrating WhatsApp communications and files from compromised systems.
Exfiltration tool that recursively searches Desktop/Downloads and non-C drives for predefined extensions; latest variant targets WhatsApp Desktop 'Shared\transfers' path to steal WhatsApp-shared files (documents, images, archives, and mail data like PST/OST).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.