MOPSLED is a modular shellcode-based backdoor documented in ATT&CK as malware used by Chinese espionage activity, including UNC3886; Mandiant also observed sharing of MOPSLED between Chinese cyber espionage groups including APT41. It can communicate over HTTP or a custom binary protocol over TCP, retrieve plugins from its C2 server to expand functionality, and use a custom ChaCha20 implementation to decrypt embedded and external configuration data. The malware can retrieve a command-and-control address from a dead drop URL. In UNC3886 intrusions, a Linux variant, MOPSLED.LINUX, was observed on vCenter servers and on a small number of compromised endpoints where REPTILE already existed. That variant used a GitHub dead-drop URL to obtain the real C2 address; one observed sample issued HTTP GET requests to https://cyberponke.github[.]io/*, decrypted the response with ChaCha20 to recover the actual C2 IP, and then switched to a custom binary protocol similar to HTTP/S for subsequent communications. Mandiant assessed MOPSLED to be an evolution of CROSSWALK, which can act as a network proxy. In the observed VMware-focused activity, MOPSLED.LINUX appeared to be used after access was already gained and lacked rootkit-like stealth capabilities, which likely limited its use. The broader UNC3886 campaign targeted VMware environments and relied heavily on valid credential collection and lateral movement across guest VMs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...either through the collection of vpxuser credentials or by exploiting CVE-2023-20867 in conjunction with VMware Guest Operations abuse to facilitate malicious file transfer and execution..."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The threat actor was observed deploying malware, including MOPSLED and RIFLESPINE, that leverages trusted third parties like GitHub and Google Drive as C2 channels..."
"The threat actor was observed deploying malware, including MOPSLED and RIFLESPINE, that leverages trusted third parties like GitHub and Google Drive as C2 channels..."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
"...deploying malware, including MOPSLED and RIFLESPINE, that leverages trusted third parties like GitHub and Google Drive as C2 channels while relying on the rootkits for persistence."
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... MOPSLED ... (v1.0) ...
MOPSLED (v1.0)
Malware capable of retrieving a C2 address from a dead-drop URL.
Malware that uses a custom binary protocol over TCP for command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.