POORAIM is a malware family associated with screen capture and process discovery on compromised Windows systems. Documented capabilities include enumerating running processes and capturing screenshots of the victim desktop, indicating use for host reconnaissance and visual surveillance after compromise. POORAIM has also been observed using AOL Instant Messenger as a command-and-control channel, reflecting an effort to blend malicious communications with legitimate online services. Delivery has been linked to compromised websites used as watering holes, suggesting targeted web-based initial access against selected victims. The available reporting supports classifying POORAIM as a remote-access-style implant used for post-compromise collection and operator visibility on infected hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware capable of screen capture.
Backdoor malware capable of enumerating processes.
Backdoor malware capable of screen capture.
Backdoor that uses AOL Instant Messenger as a command-and-control channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.