COMpfun is a Windows malware family associated with stealthy persistence through COM object hijacking and used in espionage-oriented intrusions. It has been described both as a remote access trojan and, in some distribution chains, as a downloader for follow-on payloads. The malware achieves persistence by hijacking COM class registrations so that Windows loads an attacker-controlled library in place of a legitimate component, allowing execution inside normal user processes without conventional DLL injection. This approach is notably quiet, blends into standard process activity, and has been observed as a long-term covert foothold mechanism.
COMpfun-related activity has been linked with medium-to-low confidence to Turla based on code similarities, tradecraft, and victimology. Reported targeting has included European diplomatic entities, and related tooling derived from the same code base has been used in broader espionage campaigns. Researchers also identified strong code overlap between COMpfun and Reductor, assessing that Reductor was likely developed by the same authors. In at least one observed infection path, already infected COMpfun hosts were used to download Reductor components, indicating COMpfun can function as a staging mechanism for additional malware.
A later COMpfun-related Trojan variant used an unusual command-and-control design based on uncommon HTTP or HTTPS status codes to queue and trigger actions. Reported capabilities for this code base include host fingerprinting, command execution, file upload and download, keylogging, screenshot capture, clipboard collection, network resource enumeration, USB propagation, process injection, and encrypted exfiltration. The malware also incorporates anti-analysis checks for virtualized environments, debuggers, and security tooling. Across reporting, COMpfun and closely related variants consistently target Windows systems and are characterized by stealthy persistence, covert surveillance, and post-compromise control in support of intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Kaspersky Attribution Engine shows strong code similarities between this family and the COMPfun Trojan. Moreover, further research showed that the original COMpfun Trojan most probably is used as a downloader in one of the distribution schemes.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
In other words, it’s a normal full-fledged Trojan that is also capable of propagating itself to removable devices.
As with all modules with a similar code base, the dropper begins by dynamically resolving all the required Windows API function addresses and puts them into structures.
The file name related to the visa application process perfectly corresponds with the targeted diplomatic entities.
The module then chooses a process to inject the code into, in order of decreasing priority, starting from Windows (cmd.exe, smss.exe), security-related applications ... and browsers
It then decrypts the next stage malware from its resource (.rsrc) section. The algorithm used to decrypt the next stage is a one-byte XOR using the key “0x55”, followed by LZNT1 decompression.
424 Failed Dependency (WebDAV) Fingerprint target. Send host, network and geolocation data
The module obtains the processor architecture (32- or 64-bit) and Windows OS version.
If initialization is successful, the malware starts one more thread for dispatching Windows messages, looking for removable devices related to a WM_DEVICECHANGE event.
It includes a number of anti-analysis checks for virtual machine-related devices (VEN_VMWARE, VBOX_HARDDISK, Virtual_DVD_ROM, etc.) to avoid controlled execution.
It also notes which security products are running on the host (Symantec, Kaspersky, Dr.Web, Avast).
Its functions include the ability to acquire the target’s geolocation, gathering host- and network-related data, keylogging and screenshots.
We observed an interesting C2 communication protocol utilizing rare HTTP/HTTPS status codes ... Several HTTP status codes (422-429) from the Client Error class let the Trojan know what the operators want to do.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A full-featured Trojan/backdoor family associated in the content with diplomatic targeting. It gathers host, network and geolocation data, performs keylogging and screenshots, propagates via removable devices, uses COM-hijacking persistence, and communicates with C2 over HTTP/HTTPS using unusual HTTP status codes as commands.
A Trojan initially documented in 2014 that is described here as code-related to Reductor and likely used as a downloader to deliver Reductor onto already infected hosts, with COM CLSID persistence and the ability to download additional modules from C2.
A suspected Turla RAT variant controlled using uncommon HTTP status codes and deployed against European diplomatic entities.
Trojan family using spoofed visa-application lures; staged dropper downloads payload that performs host/network discovery, keylogging, screenshots, USB monitoring/infection, and uses HTTP status codes for C2 commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.