VtChatter is a malware/backdoor used by the China-linked APT31 threat group (also tracked as Judgment Panda, TA412, and Violet Typhoon) in cyber-espionage operations. Reporting ties it to APT31 intrusions targeting Russia’s IT sector, especially contractors and integrators for government agencies, during activity spanning at least late 2022 through 2025. Its notable capability is using VirusTotal as a covert command-and-control channel: it exchanges Base64-encoded comments via a text file hosted on VirusTotal, operating as a two-way C2 channel approximately every two hours. The malware is part of a broader APT31 toolset that relied on legitimate cloud and internet services to blend into normal traffic and evade detection. High-confidence context associates the broader campaign with spear-phishing, archive-based lures, LNK execution, and DLL sideloading, though the provided content does not explicitly state the precise initial infection vector specific to VtChatter itself. The campaign was espionage-focused and aimed at collecting sensitive information from victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VtChatter, a tool that uses Base64-encoded comments to a text file hosted on VirusTotal as a two-way C2 channel every two hours
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor malware used by APT31 that abuses the VirusTotal commenting system as a covert C2 channel, allowing attackers to communicate with infected hosts in a stealthy manner.
C2 mechanism that polls/uses Base64-encoded comments in a VirusTotal-hosted text file for bidirectional communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.