Mis-Type is a Windows backdoor associated with post-compromise reconnaissance, command-and-control resilience, data staging, and data exfiltration. It communicates with operators using Base64-encoded traffic and can use a raw TCP socket as its primary command-and-control channel, with a fallback to an HTTP-based protocol and alternate server when the primary method fails. This dual-channel design supports continued operator access when network conditions or defenses disrupt one transport.
On infected systems, Mis-Type performs host and user-context discovery. Reported behaviors include determining the privilege level of the compromised user, collecting local network configuration information through commands such as ipconfig /all, and querying account information with net user. It temporarily stores collected information in local files before transmitting the results to command-and-control infrastructure, indicating a staged collection-and-exfiltration workflow.
Mis-Type also employs defense-evasion techniques. It has been observed injecting itself into legitimate running processes, including explorer.exe, and masquerading as a legitimate Windows component by saving itself under the name of a Microsoft service binary. Additional reported behavior includes creating a temporary local user account, which may support persistence or follow-on operator activity.
Overall, Mis-Type is best characterized as a Windows backdoor used for interactive post-exploitation, host reconnaissance, covert communications, and exfiltration, with process injection and masquerading used to reduce detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Machete has sent data over HTTP if FTP failed. Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol. NETEAGLE will send beacons via an HTTP POST request if the infected host is configured to a proxy.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware observed being injected directly into running processes such as explorer.exe.
Backdoor that tests the privilege level of the compromised user.
Captures ipconfig /all output to a file for network configuration discovery.
Backdoor that captures ipconfig /all output to a file for network configuration discovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.