Skip to main content
Mallory
MalwareUsed by 2 actors

LightRail

LIGHTRAIL is a custom tunneling malware used for covert command-and-control and data exfiltration. Reporting describes it as likely based on Lastenzug, an open-source Socks4a proxy, and communicating through Azure cloud infrastructure, including hardcoded WebSocket parameters, to blend malicious traffic with legitimate cloud activity. It has been associated with the Iran-linked espionage cluster UNC1549, which overlaps with Tortoiseshell and has also been described as Nimbus Manticore and Subtle Snail. LIGHTRAIL has been used in espionage intrusions targeting aerospace, aviation, defense, telecommunications, and related sectors across the Middle East, Europe, and other regions. It has also been referenced in broader reporting on Tortoiseshell tooling. Observed tradecraft includes delivery and execution via DLL search order hijacking: one reported case involved a ZIP archive containing the LIGHTRAIL payload as VGAuth.dll, executed through VGAuthCLI.exe. LIGHTRAIL is frequently mentioned alongside other UNC1549/Tortoiseshell tools including GHOSTLINE, POLLBLEND, MINIBIKE, TWOSTROKE, DEEPROOT, DCSYNCER.SLICK, CRASHPAD, and SIGHTGRAB. High-confidence behavioral characterization from the source material is that LIGHTRAIL functions as a stealthy tunneler that disguises malicious communications within legitimate cloud traffic to support resilient connectivity and covert exfiltration.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Magic Hound

LIGHTRAIL — A tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.

via mandiant blogmandiant.com
Subtle Snail

"LIGHTRAIL, a custom tunneler that's likely based on Lastenzug, an open-source Socks4a proxy that communicates using Azure cloud infrastructure"

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.001DomainsEvidence1

This suspected UNC1549 campaign deployed several evasion techniques to mask their activity: Abusing Microsoft Azure infrastructure for C2 and hosting, making it difficult to discern the activity from legitimate network traffic.

Execution

1 technique
T1574.001DLLEvidence1

"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."

Stealth

2 techniques
T1036MasqueradingEvidence1
TacticStealth

A benign lure in the form of an application like OneDrive (MINIBIKE) or, in the case of MINIBUS, a custom application presenting content related to Israelis kidnapped by Hamas... Using domain naming schemes that include strings that would likely seem legitimate to network defenders.

T1574.001DLLEvidence1

"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."

T1071Application Layer ProtocolEvidence1

Payload installation and device compromise, achieved after the MINIBIKE or MINIBUS backdoors establish C2 communication, in most cases via Microsoft Azure cloud infrastructure.

T1090ProxyEvidence1

LIGHTRAIL, a unique tunneler used in the campaign... LIGHTRAIL likely leverages the open-source utility “Lastenzug” ... a Socks4a proxy based on websockets.

T1572Protocol TunnelingEvidence1

fallback channels and protocol tunneling tools such as Ngrok and ZeroTier ensured continuity

INDICATORS OF COMPROMISE

IOCs tracked for this family

7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
6 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app2 years ago
hash.md5●●●●●●●●●●●●View more in app2 years ago
hash.md5●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app2 years ago
hash.md5●●●●●●●●●●●●View more in app2 years ago
hash.md5●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching7

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.