NDiskMonitor is a malware family associated with Patchwork activity. It has been observed collecting the victim username and transmitting that information to command-and-control infrastructure. Its command-and-control communications include AES encryption for at least some transmitted data, indicating an effort to protect or obfuscate operator traffic. Patchwork operators have also reportedly modified NDiskMonitor samples by inserting random bytes to alter file hashes, a straightforward anti-detection measure intended to reduce the usefulness of static signatures. The available evidence supports NDiskMonitor as a Windows malware used in targeted intrusion activity, with confirmed host reconnaissance focused on user identity collection and encrypted C2 exchanges.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that obtains the victim username and encrypts it for C2 transmission.
Obtains the victim username and encrypts it for transmission over C2.
Backdoor that uses AES to encrypt some data sent over its C2 channel.
A surveillance tool used for monitoring disk activity and potentially exfiltrating data, used by Patchwork.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.