Supper is a small Windows backdoor, also known as SocksShell, WINDYTWIST, and ZAPCAT, used to maintain persistent post-compromise access. It provides operators with remote command-line access, supports command execution through cmd.exe, and can execute supplied DLL payloads. Variants implement encrypted command-and-control communications, self-deletion, and SOCKS5 proxying or tunneling, enabling operators to route traffic through compromised hosts.
Supper has been associated with financially motivated ransomware intrusions involving Vanilla Tempest and Storm-0494, including activity preceding deployment of Rhysida and INC ransomware. It has also appeared in reporting on Interlock-linked activity, although shared tooling and code overlap do not establish exclusive ownership by any one group. Supper is commonly deployed after initial access obtained through Gootloader, trojanized software installers, fake download pages, or ClickFix and fake-CAPTCHA social-engineering chains.
Operators using Supper have conducted host, network, and Active Directory discovery, including enumeration of domains, domain controllers, trust relationships, privileged groups, local administrators, system configuration, and network settings. Observed intrusions have also used Supper to support hands-on-keyboard post-exploitation, remote access, lateral movement preparation, and ransomware operations. Supper primarily targets Windows enterprise environments; reported victim sectors associated with its ransomware ecosystem include healthcare, education, government, IT, and manufacturing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Supper backdoor... has been reported as a custom backdoor used by Vanilla Tempest to enable a foothold prior to the deployment of ransomware.
Lorem Ipsum appears to be a parallel or successor loader within Rapid Brigantine's expanding toolkit, culminating in handoff to their documented post-exploitation arsenal (Supper, Oyster, MeowBackConn) and ultimately to Rhysida ransomware deployment.
Storm-0494 deploys backdoors like Supper (SocksShell or ZAPCAT) and AnyDesk for remote access, further compromising networks.
X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
"As a persistence mechanism, the sample added itself as a Windows scheduled tasks: schtasks.exe /Create /SC MINUTE /TN GoogleUpdateTask ..."
Its main purpose is to provide threat actors with command line access to a victim (enabling “hands on keyboard” activity).
"The operators used PowerShell and native Windows utilities to identify the domain, enumerate machines, discover domain controllers and examine privileged groups."
The operators used "nltest /dclist:<domain>" and PowerShell "DirectoryServices.DirectorySearcher" to enumerate domain computers.
"The ability to proxy traffic through the infected machine allows threat actors to map the internal network stealthily"
"Other supported commands include, at minimum, a SOCKS proxy feature"; YARA strings include "bad socks5 request" and "Starting Init SOCKS"
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Persistent post-compromise backdoor in the Rhysida-related ecosystem. Operators used it for hands-on-keyboard activity, including Active Directory, domain-controller, domain-trust, privileged-group, system, and network discovery.
A custom backdoor reportedly used by Vanilla Tempest to establish an initial foothold before ransomware deployment. It is mentioned because a prior Supper case used the same Active Directory account-enumeration query observed in this activity.
A backdoor used by both Interlock and Rhysida that maintains persistent access, creates encrypted tunnels, and executes remote shell commands. IBM found it shares command structures, C2 registration formats, and self-deletion behavior with InterlockRAT.
A post-exploitation SOCKS5 backdoor/tool in Rapid Brigantine's arsenal, mentioned as downstream tooling associated with Lorem Ipsum-enabled intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.