Supper is a backdoor malware family, also referred to in reporting as SocksShell, WINDYTWIST, and ZAPCAT. It is commonly described as a SOCKS5 backdoor used to provide persistent remote access to compromised systems, including encrypted tunneling, proxying, and remote shell execution. Reported capabilities include SOCKS proxy setup and disconnection, shell execution, self-deletion, custom-encrypted command-and-control communications, and persistence via either scheduled tasks or Run-key mechanisms depending on the observed variant. Public reporting also notes obfuscation and anti-analysis features such as API hammering, API hashing, runtime shellcode reconstruction, hash-based DLL resolution, custom compression/decompression, and structured C2 handling.
Supper has been observed as a post-compromise payload and is frequently characterized as pre-ransomware tooling. It has been deployed after initial access from GootLoader/Storm-0494 activity, ClickFix/Fake CAPTCHA social engineering, trojanized installers, fake Microsoft Teams download pages, traffic-distribution systems, and malvertising/SEO-poisoning campaigns. It has also been delivered by the pkr_mtsi packer, which has distributed Supper alongside Oyster, Vidar, and Vanguard Stealer.
The malware is strongly associated in the provided reporting with financially motivated ransomware operations and related clusters, especially Vanilla Tempest (also tracked as Rapid Brigantine, DEV-0832, Vice Society, and linked in reporting to Rhysida activity), as well as overlaps between Rhysida and Interlock. IBM X-Force reported that Supper was shared across Interlock and Rhysida-linked activity and found code and behavioral similarities between Supper and InterlockRAT, including nearly identical command structures, similar C2 registration formats, and the same self-deletion method. Huntress and Microsoft reporting describe Supper as a recurring backdoor in Vanilla Tempest intrusions, including attacks that later deployed Rhysida or INC ransomware.
Observed post-compromise use includes remote access, internal reconnaissance, lateral movement support, and staging for ransomware deployment. In reported healthcare intrusions, attackers installed Supper and then used legitimate tools such as AnyDesk and MEGA, along with RDP, WMI Provider Host, WinRM, and Impacket, before deploying ransomware. Sectors mentioned in associated campaigns include healthcare, education, government, IT, and manufacturing, with many victims in the United States.
High-confidence indicators and technical details directly mentioned in the content include DLL samples 245282244.dll (SHA-256: 2528df60e55f210a6396dd7740d76afe30d5e9e8684a5b8a02a63bdcb5041bfc) and 760468301.dll (SHA-256: 21b953dc06933a69bcb2e0ea2839b47288fc8f577e183c95a13fc3905061b4e6), both identified as Supper; use of DllRegisterServer as the main exported function in those samples; scheduled-task persistence via a task named GoogleUpdateTask; and reported C2 endpoints including 162.19.199.110:4043, 146.19.49.130:8080, 185.233.166.27:443, and 85.239.54.130. Other reporting in the content notes Supper communicating over TCP 443 with custom XOR-encrypted messages using a per-message 4-byte key.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lorem Ipsum appears to be a parallel or successor loader within Rapid Brigantine's expanding toolkit, culminating in handoff to their documented post-exploitation arsenal (Supper, Oyster, MeowBackConn) and ultimately to Rhysida ransomware deployment.
According to X-Force, the clearest overlap is the shared use of the Supper backdoor, also known as SocksShell or WINDYTWIST, which has appeared in confirmed incidents tied to both ransomware operations.
Storm-0494 deploys backdoors like Supper (SocksShell or ZAPCAT) and AnyDesk for remote access, further compromising networks.
X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware...
12 distinct techniques documented for this family, organized by ATT&CK tactic.
"As a persistence mechanism, the sample added itself as a Windows scheduled tasks: schtasks.exe /Create /SC MINUTE /TN GoogleUpdateTask ..."
"...copying a specific PowerShell script and executing it manually via the Windows Run dialog..."; "the initial PowerShell command retrieves a malicious payload from a remote domain"
"The ability to proxy traffic through the infected machine allows threat actors to map the internal network stealthily"
"Other supported commands include, at minimum, a SOCKS proxy feature"; YARA strings include "bad socks5 request" and "Starting Init SOCKS"
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used by both Interlock and Rhysida that maintains persistent access, creates encrypted tunnels, and executes remote shell commands. IBM found it shares command structures, C2 registration formats, and self-deletion behavior with InterlockRAT.
A post-exploitation SOCKS5 backdoor/tool in Rapid Brigantine's arsenal, mentioned as downstream tooling associated with Lorem Ipsum-enabled intrusions.
Referenced as a secondary payload family used post-compromise; associated with C2 infrastructure and described as supporting data exfiltration/lateral movement and potential ransomware deployment in the campaign.
Supper is a Windows malware family used for persistence and remote control. In this incident it established persistence via a scheduled task, communicated with hardcoded/updated C2 IP:port infrastructure using a custom encrypted protocol (XOR 'M' header + custom stream-like cipher), supported at least C2 server list updates, a SOCKS proxy feature, and execution of custom binaries delivered from C2 (suggesting a loader/backdoor role commonly used ahead of follow-on payloads, including ransomware).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.