CORNFLAKE.V3 is a Windows-focused backdoor attributed to the financially motivated UNC5774 cluster and used following initial access obtained through UNC5518’s access-as-a-service operations. It is an evolution of CORNFLAKE.V2 and has JavaScript and PHP variants. The backdoor retrieves follow-on payloads over HTTP, writes and executes them, and supports shell commands, executables, DLLs, JavaScript, batch scripts, and PowerShell commands. It gathers basic host information and transmits it to remote infrastructure over HTTP, with observed use of Cloudflare Tunnels to proxy command-and-control traffic. CORNFLAKE.V3 adds host persistence through Windows Registry Run-key execution. It has been deployed through ClickFix campaigns in which compromised legitimate websites, malicious advertising, or search-engine poisoning direct victims to fraudulent CAPTCHA pages that induce execution of a malicious PowerShell command through the Windows Run dialog. Follow-on tooling delivered through CORNFLAKE.V3 has included credential-harvesting tooling, Active Directory reconnaissance utilities, and the WINDYTWIST.SEA backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5774 is identified as a known downstream UNC5518 customer that deploys the CORNFLAKE.V3 backdoor as a loader for follow-on payloads.
...fraudulent CAPTCHA pages to inject the CORNFLAKE.V3 backdoor as part of a ClickFix attack campaign...
6 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used by UNC5774 as a loader for subsequent payloads. It is contextual attribution information and is not the payload observed in this incident.
Backdoor deployed via ClickFix social engineering and fake CAPTCHA pages to provide initial access/persistent access as part of an access-as-a-service scheme.
Versatile backdoor deployed via ClickFix/fake CAPTCHA social engineering as part of access-as-a-service activity (per excerpt).
CORNFLAKE.V3 is the third version of the CORNFLAKE backdoor, used by multiple threat actors for persistent access and espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.