Final1stspy is a Windows malware family with spyware-like backdoor characteristics. Documented behavior includes enumerating running processes for host discovery, deobfuscating embedded Base64-encoded strings during execution, establishing persistence through a Registry Run autostart entry, and communicating with command-and-control infrastructure over HTTP. These traits indicate an implant designed to survive reboots, profile the victim environment, and maintain remote operator connectivity while concealing parts of its configuration or logic through lightweight string obfuscation. High-confidence reporting supports Windows as the target platform due to its use of Registry-based persistence and process enumeration on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that uses Python code to deobfuscate Base64-encoded strings.
Malware that establishes persistence by creating a Registry Run key.
Spyware that obtains a list of running processes.
Malware that uses Python to deobfuscate Base64-encoded strings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.