metaMain is a Windows in-memory backdoor associated with the Metador espionage threat actor. It was used in operations targeting telecommunications providers, internet service providers, and universities, particularly in the Middle East and Africa, as part of long-term access and intelligence collection activity. The implant is designed to avoid writing unencrypted components to disk and to operate through reflective loading and process injection, contributing to a stealth-focused intrusion chain.
metaMain supports multiple execution methods, including DLL sideloading, and has been observed in an infection chain that abused the Microsoft Console Debugger to inject shellcode into a legitimate process and load encrypted components entirely in memory. It can act both as a standalone backdoor and as a loader for the related Mafalda framework. Reported capabilities include collecting the username from a compromised host, keylogging, screenshot capture, local data collection and staging, uploading collected files and data to command-and-control infrastructure, creating named-pipe-based command channels, and establishing indirect or raw TCP socket communications. It also supports reflective DLL loading and process injection.
For persistence, metaMain has been observed registering a WMI event subscription consumer. For defense evasion and anti-forensics, it can modify file timestamps when running with elevated privileges and is associated with encrypted communications and in-memory execution patterns intended to reduce forensic visibility. metaMain is part of a broader Metador toolset characterized by segmented infrastructure, stealthy command and control, and redundant access mechanisms aligned with espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Metador has used unique malware in their operations, including metaMain and Mafalda.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
metaMain... provides operators with extensive functionality... and the ability to execute arbitrary shellcode. ... The functionalities of the backdoor commands have a very broad scope and include credential theft, data and information theft, command execution...
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
When the TCP KNOCK communication method is enabled, the metaMain and Mafalda implants can establish an indirect connection to the C2 server through another implant... metaMain and Mafalda authenticate themselves to Cryshell through a port-knocking and handshake procedure.
In this case, metaMain’s persistence relies on the abuse of WMI Event Subscriptions. The operators register an event consumer named hard_disk_stat. Five to six minutes after booting up, the event triggers the execution of a LOLbin, cdb.exe.
A debugging script, cdb.ini, is used to inject a small amount of shellcode into the debugged process in order to load metaMain.
In this case, metaMain’s persistence relies on the abuse of WMI Event Subscriptions. The operators register an event consumer named hard_disk_stat. Five to six minutes after booting up, the event triggers the execution of a LOLbin, cdb.exe.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
A debugging script, cdb.ini, is used to inject a small amount of shellcode into the debugged process in order to load metaMain.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.' | Several entries explicitly state files were deleted after exfiltration or upload, such as 'AppleSeed can delete files from a compromised host after they are exfiltrated,' 'Attor’s plugin deletes the collected files and log files after exfiltration,' and 'Ursnif has deleted data staged in tmp files after exfiltration.'
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
When the TCP KNOCK communication method is enabled, the metaMain and Mafalda implants can establish an indirect connection to the C2 server through another implant... metaMain and Mafalda authenticate themselves to Cryshell through a port-knocking and handshake procedure.
Among them, we noticed the use of an unusual LOLbin, the Microsoft Console Debugger cdb.exe. CDB was the root of an intricate infection chain that would yield two in-memory malware platforms... The attackers used the following command line: cdb.exe -cf c:\windows\system32\cdb.ini c:\windows\system32\defrag.exe -module fcache13.db
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
metaMain is an implant framework used to maintain long-term access to compromised machines. It provides operators with extensive functionality, like keyboard and mouse event logging...
That IP is utilized for command-and-control over either HTTP (metaMain, Mafalda) or raw TCP (Mafalda).
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
‘Cryshell’– a custom implant used for bouncing connections in an internal network to external command-and-control servers... When the TCP KNOCK communication method is enabled, the metaMain and Mafalda implants can establish an indirect connection to the C2 server through another implant.
metaMain is an implant framework used to maintain long-term access to compromised machines. It provides operators with extensive functionality, like ... file download and upload...
When the TCP KNOCK communication method is enabled, the metaMain and Mafalda implants can establish an indirect connection to the C2 server through another implant... metaMain and Mafalda authenticate themselves to Cryshell through a port-knocking and handshake procedure.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows in-memory implant framework used to maintain long-term access to compromised machines. It provides backdoor capabilities including keyboard and mouse logging, screenshot theft, file upload/download, and arbitrary shellcode execution. It can also act as a loader for Mafalda and supports multiple execution flows including CDB_DEBUGGER, HKCMD_SIDELOADING, and KL_INJECTED.
Unique malware used in Metador operations.
Malware that can alter multiple Windows file time attributes when running with SYSTEM privileges.
Malware that injects a loader file named Speech02.db into a process.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.