QuietEnvelope is a malware toolset identified by ESET that was specifically developed to target the MailGates email protection system of OpenFind email servers. The reported toolset includes Perl scripts, three stealthy backdoors, and other miscellaneous files. One documented component is an LKM backdoor that monitors TCP port 6400 for a magic string and then executes commands. ESET assessed the activity as very likely the work of a Chinese APT, and debug strings written in simplified Chinese were cited as suggesting a Mainland China origin. The available reporting directly ties QuietEnvelope to attacks against OpenFind MailGates email infrastructure; no additional victim sectors, infection vectors, or confirmed indicators beyond TCP port 6400 and the magic-string-triggered command execution behavior were provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated toolset targeting OpenFind MailGates email servers, including Perl scripts and three stealthy backdoors (LKM, Apache module, injected shellcode) for persistent remote access.
A malware strain developed to target the MailGates email protection system of OpenFind email servers, likely used in targeted attacks by a Chinese APT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.