LIONTAIL is a Windows-focused malware framework comprising custom shellcode loaders and memory-resident shellcode implants. It abuses undocumented behavior in the Windows HTTP.sys driver to listen for, intercept, decode, and retrieve attacker-selected payloads from inbound HTTP traffic matching defined URL patterns. The framework can be tailored to individual compromised servers and may use reverse proxies and reverse shells to make malicious communications resemble legitimate HTTP activity. LIONTAIL has been attributed to Scarred Manticore, an Iranian state-linked threat actor associated with OilRig (APT34), in intrusions targeting government and telecommunications organizations in the Middle East. It has been observed resident in memory on critical Windows servers, supporting stealthy, long-term access while reducing filesystem-based detection opportunities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LIONTAIL is a malware framework that includes a set of custom shellcode loaders and memory resident shellcode payloads. It takes advantage of undocumented functionalities of the HTTP.sys driver to extract payloads from incoming HTTP traffic.
...including the LionTail framework, TEMPLEDOOR, SASHEYAWAY, and a repurposed Windows kernel driver... designed to sustain long-term, low-visibility access.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The advisory identifies Obfuscated Files or Information under Defence Evasion.
Эти компоненты внедряют вредоносные DLL-библиотеки Eternalblue2.dll и Doublepulsar2.dll в процессы lsass.exe и explorer.exe...
This may indicate that the attacker exploited a vulnerability in the web application to gain remote code execution, allowing them to establish a reliable command and control channel that bypassed the firewall because it was initiated from inside the network.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Сложный фреймворк из кастомных загрузчиков и резидентных имплантов, работающих в памяти; использует особенности HTTP.sys для скрытой доставки полезной нагрузки через HTTP-трафик.
A sophisticated in-memory framework of custom loaders and shellcode implants that abuses undocumented HTTP.sys behavior to covertly deliver/retrieve payloads over inbound HTTP and blend malicious traffic into legitimate flows.
ShroudedSnooper framework for passive backdoors and web shells enabling long-term stealthy access.
Custom loader and memory-resident shellcode framework used by OilRig for advanced evasion and payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.