Pasam is a malware family identified as a backdoor that enables remote operators to interact with compromised systems. Documented capabilities include retrieving files from an infected host, deleting files, and obtaining lists of running processes. This combination of remote file access and process enumeration indicates use in post-compromise control, host reconnaissance, and operational management of victim machines. Available information supports its role as a simple remote-access backdoor, but does not provide high-confidence detail on delivery mechanism, associated threat actor, or specific industry targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... Pasam ... (v1.1→v1.2) ...
Pasam (v1.1→v1.2)
Backdoor malware that allows remote attackers to retrieve files from infected systems.
Backdoor malware enabling remote file deletion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.