LIDSHOT is a malware family associated with the UNC2970 threat cluster, which Mandiant linked to TEMP.Hermit. It is part of a broader UNC2970 toolset that includes PLANKWALK, LIDSHIFT, TOUCHSHIFT, TOUCHSHOT, TOUCHKEY, HOOKSHOT, TOUCHMOVE, SIDESHOW, and CLOUDBURST. UNC2970 has been reported targeting the defense, media, and technology sectors, and Mandiant assessed the group may have expanded targeting to include security researchers.
The provided content identifies LIDSHOT as an implant with dedicated detection content, including YARA rules and IOC signatures, and references LIDSHOT command-and-control infrastructure. One described infection chain states that a preceding component injects a DLL disguised as a Notepad++ plugin and then loads LIDSHOT. In that context, the preceding malware is described as a downloader capable of system enumeration and deployment of additional malicious payloads on the compromised host.
High-confidence indicators directly provided for LIDSHOT include the file hash 41dcd8db4371574453561251701107bc. The content also notes the existence of LIDSHOT C2-related detections, but does not provide a specific LIDSHOT C2 URL in the supplied material. Overall, LIDSHOT should be understood as part of an actively developed UNC2970 malware ecosystem used in intrusion activity against enterprise targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
IOC Signature ... LIDSHOT ... LIDSHOT C2 ... LIDSHOT rule ... "Detects LIDSHOT implant"
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.