pngdowner is a Windows malware family that communicates with command-and-control infrastructure over HTTP. It includes logic to support operation in proxied enterprise environments: when an initial connectivity check fails, it attempts to recover proxy configuration details and associated credentials from Windows Protected Storage and the Internet Explorer Credentials Store, then uses those credentials to enable subsequent outbound HTTP communications where proxy authentication is required. The malware has also been observed deleting content from command-and-control communications after that content is saved to the user temporary directory, indicating cleanup and anti-forensic behavior. The documented behavior supports characterization of pngdowner as a credential-stealing implant with command-and-control and defense-evasion functionality on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader malware that deletes saved C2 communication content from temporary storage.
Backdoor that can extract proxy details and credentials from Windows Protected Storage and Internet Explorer credential storage to enable outbound access.
Backdoor that extracts proxy details and credentials from Windows Protected Storage and the IE Credentials Store to enable outbound access.
Malware that uses HTTP for command-and-control (C2).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.