Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SNOWYAMBER first appeared in October 2022. It is a dropper that uses the business collaboration tool Notion for communications and deploys Cobalt Strike and BruteRatel as second-stage payloads.
It’s worth noting that the string encryption algorithms appear to line up with those seen within the Cloaked Ursa SNOWYAMBER and QUARTERRIG malware reports by the Military Counterintelligence Service and CERT.PL.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
For communication, the payload uses both the Microsoft Graph and Dropbox API... If communication fails via the Graph API several times, communication via Dropbox is attempted.
SNOWYAMBER – a tool first used in October 2022, abusing the Notion service to communicate and download further malicious files.
SNOWYAMBER first appeared in October 2022. It is a dropper ... that uses the business collaboration tool Notion for communications and deploys Cobalt Strike and BruteRatel ... as second-stage payloads.
Previously, Cloaked Ursa-linked payloads that communicate with Dropbox had wrapped communications in a packet that resembled an MP3 file... In this sample, it appears that they have opted to use BMP files. The threat actor-owned C2 will upload commands to Dropbox that are wrapped in the BMP format.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A dropper first seen in October 2022 that communicates via Notion and delivers second-stage payloads including Cobalt Strike and BruteRatel. A newer version appeared in February 2023 with added operational security features.
A Cloaked Ursa-linked malware family referenced due to shared string-encryption and obfuscation techniques with the analyzed payloads.
A downloader first used in October 2022 that abuses Notion for communications and retrieval of additional malicious files. It also sends host and user details for victim triage before delivering follow-on tooling.
Downloader installed by EnvyScout to retrieve additional payloads in APT29 intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.