IceApple is a modular IIS-based post-exploitation framework associated with intrusions involving Microsoft Exchange and other IIS-hosted environments. It is implemented as malicious .NET assemblies and IIS components that execute within web server worker processes, enabling operators to run follow-on capability inside compromised server contexts while minimizing conventional process-spawn artifacts. The framework has been observed using reflective code loading to load additional .NET modules into Exchange application pools, and its assemblies have used legitimate-looking naming conventions to blend into ASP.NET and IIS environments.
IceApple provides a broad set of post-compromise capabilities centered on credential access, Active Directory discovery, collection, and exfiltration. Documented modules can harvest credentials from local and remote Windows registries, dump LSA secrets, and extract encrypted password hashes from SAM-related registry data. It also includes an Active Directory querying capability that performs authenticated requests against domain services to enumerate directory information. For collection and theft, IceApple can gather files, passwords, and other data from compromised hosts, compress and encrypt data prior to transfer, and exfiltrate multiple files over existing command-and-control communications using HTTP responses.
The framework also employs defense-evasion measures. Reported tradecraft includes Base64 and junk JavaScript obfuscation, reflective in-memory loading of .NET assemblies, and masquerading through benign-looking assembly names. Its use as an IIS module and in-memory .NET loader makes it particularly relevant to server-side compromises where attackers seek stealthy persistence and durable post-exploitation access on Windows web infrastructure. High-confidence reporting places IceApple in the context of malicious IIS module activity and Exchange server intrusions rather than commodity malware distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
"Brute Ratel C4 has used reflective loading to execute malicious DLLs." / "Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process..." / "FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory."
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
Adversaries may search the Registry on compromised systems for insecurely stored credentials... Example commands to find Registry keys related to password information: Local Machine Hive: reg query HKLM /f password /t REG_SZ /s Current User Hive: reg query HKCU /f password /t REG_SZ /s
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. Sandworm Team has used a tool to query Active Directory using LDAP.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Multiple actors and tools are described enumerating domain users/admins via Windows net commands (e.g., net user /domain, net group "Domain Admins" /domain), LDAP/AD queries (e.g., Get-ADUser, Get-ADGroupMember), and AD enumeration utilities (e.g., AdFind, BloodHound, AD Explorer).
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
Multiple actors and tools are described as using 7-Zip/WinRAR/zip/tar/gzip/makecab/PowerShell Compress-Archive to compress (often password-protect/encrypt) collected data prior to exfiltration (e.g., “used 7zip to archive extracted data in preparation for exfiltration”, “created password-protected RAR archives prior to exfiltration”, “used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data”).
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IIS-based post-exploitation framework referenced in the detection context for malicious IIS modules and web-shell-like persistence.
A novel Internet Information Services (IIS) post-exploitation framework implemented via IIS modules, associated with persistence and arbitrary code execution on compromised IIS servers.
Referenced as an example of a stateful IIS post-exploitation framework using .NET/ASP.NET variables to persist between requests (not directly attributed as used by TGR-CRI-0045 in this report).
A malicious IIS module/backdoor used for persistence on IIS servers, designed to keep the base module minimally indicative while reflectively loading additional .NET modules/capabilities on demand (including potentially downloading assemblies from actor-controlled infrastructure).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.