OSInfo is a custom Windows information-discovery utility associated with APT3. It is used post-compromise to profile hosts and domains by collecting system, account, network, and share information that can support privilege assessment, lateral movement planning, and broader situational awareness inside victim environments. Reported behavior includes enumerating local and domain users, identifying privileged groups such as Domain Admins and power users, discovering the current domain, listing network shares, testing connectivity to remote systems, and enumerating active network connections in a manner similar to native Windows networking utilities. OSInfo also queries the Windows Registry for Terminal Services-related information, indicating an interest in remote access configuration and reachable systems. The tool has been described as functionally overlapping with built-in administrative commands used for account discovery, remote system discovery, network share discovery, system information discovery, system network configuration discovery, and local network connection discovery. Its known use is tied to APT3 operations targeting sectors including aerospace and defense, construction and engineering, high technology, telecommunications, transportation, and later political organizations in Hong Kong.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S0165 OSInfo [4] Account Discovery: Local Account, Account Discovery: Domain Account, Network Share Discovery, Permission Groups Discovery ... Remote System Discovery, System Information Discovery, System Network Configuration Discovery, System Network Connections Discovery
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
APT3 has a tool that can detect the existence of remote systems.
APT3 has a tool that can enumerate current network connections.
APT3 has a tool that can enumerate the permissions associated with Windows groups.
Multiple tools/actors are described using Active Directory/domain group enumeration, e.g., “AdFind can enumerate domain groups”, “net group "domain admins" /domain to enumerate domain groups”, “BloodHound can collect information about domain groups and members”, and “AD Explorer tool to enumerate groups on a victim's network.”
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
Multiple actors and tools are described enumerating domain users/admins via Windows net commands (e.g., net user /domain, net group "Domain Admins" /domain), LDAP/AD queries (e.g., Get-ADUser, Get-ADGroupMember), and AD enumeration utilities (e.g., AdFind, BloodHound, AD Explorer).
APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reconnaissance malware/tool that discovers shares on the network.
Discovers current domain information on infected systems.
Malware that queries registry data related to Terminal Services.
Malware that queries Registry data related to Terminal Services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.