FlawedGrace is a Windows remote-access trojan associated with TA505 and later CL0P-linked intrusion activity. It has been observed since at least 2017 as a secondary or later-stage payload delivered after initial compromise by TA505 distribution chains, including phishing campaigns using malicious Office documents and loaders such as ServHelper and Get2, as well as post-exploitation persistence following exploitation of public-facing software such as SolarWinds Serv-U. The malware has been used against organizations in financial services, retail, restaurants, and other enterprise sectors across multiple regions.
FlawedGrace is a full-featured RAT written in C++ and noted for object-oriented, multithreaded design. Reported functionality includes encrypted command-and-control communications, file transfer, remote script execution, remote desktop-related capability, password theft, and destructive command support. Analysis has also described a sophisticated networking subsystem and a custom virtual filesystem used for configuration management and command-and-control operations. FlawedGrace stores encrypted configuration data and uses obfuscated or encrypted files as part of its operation.
Operationally, FlawedGrace commonly appears after an earlier downloader or backdoor stage has established execution on a victim host. TA505 campaigns have delivered it through macro-enabled Office attachments, phishing lures themed around shared documents or business requests, and downloader chains involving MSI installers, scripting components, or embedded OLE objects. In other cases, attackers have used it for persistence by hijacking the RegIdleBackup scheduled task and abusing its COM handler so the RAT is loaded during system operation.
FlawedGrace is part of a broader TA505 malware ecosystem that has included ServHelper, Get2, FlawedAmmyy, SDBbot, Truebot, and CL0P-related tooling. Its repeated use across campaigns indicates it serves as a durable post-compromise access platform for hands-on operations, follow-on payload delivery, credential and data access, and broader enterprise intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...abusing the COM handler associated with it to execute malicious code, leading to FlawedGrace RAT.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The endgame: per Morphisec and corroborating research, the next-stage REBOL script leads to FlawedGrace, a full-featured remote-access trojan associated with TA505 — the point at which the operator gains hands-on control.
rule Windows_Trojan_FlawedGrace_8c5eb04b { ... threat_name = "Windows.Trojan.FlawedGrace" ... }
16 distinct techniques documented for this family, organized by ATT&CK tactic.
CL0P actors send a large volume of spear-phishing emails to employees of an organization to gain initial access.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
FlawedAmmyy / FlawedGrace remote access trojan (RAT) collects information and attempts to communicate with the Command and Control (C2) server to enable the download of additional malware components [T1071], [T1105].
Loaders send base64-encoded HTTP GET beacons (domain, user, OS, arch, process list) to the C2 and poll for tasking.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A full-featured remote access trojan used as the final payload in the MirrorBlast chain, providing operators with interactive control of compromised systems.
Like the previous two entries in this series on ComRAT v4 and FlawedGrace, I did this analysis as part of my preparation for an upcoming class on C++ reverse engineering.
Remote access trojan used by TA505 for persistence after exploitation, loaded via a hijacked scheduled task COM handler.
Remote Access Trojan; in these incidents its loader was stored as Base64-encoded strings in registry CLSID objects and executed via hijacking the RegIdleBackup scheduled task COM handler for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.