Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Behavioral detections would likely have identified the anomalous password filter DLL, wdigest reimplementation, and anomalous process injection performed by the RemoteInjector and DarkLoadLibrary loaders. | The ‘ClMgrSVC.exe’ binary is a custom variant of DarkLoadLibrary, an open-source loader used to obfuscate the loading of a dll.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source loader used to launch SystemBC.
A DLL loader used to stealthily load payloads without normal import visibility and with spoofed process naming; here it was used to load a SystemBC agent.
DarkLoadLibrary is a loader used in the intrusion to load other malware, including SystemBC. A variant was identified as ClMgrSVC.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.