LOWBALL is a Windows backdoor associated with the admin@338 threat group. It has been observed in spearphishing campaigns using malicious Microsoft Office documents that exploited CVE-2012-0158 to install the malware, including campaigns targeting traditional Chinese readers in Hong Kong-related contexts. LOWBALL is notable for abusing the legitimate Dropbox cloud storage service as its command-and-control channel, using the Dropbox API with a hardcoded bearer token and communicating over HTTPS on port 443 to blend malicious traffic with normal cloud-service usage.
The malware supports core remote-access functions including downloading, uploading, and executing files. Operators used it as an initial foothold and reconnaissance implant: after compromise, it executed command batches to collect host and network information, including operating system details, local network configuration, active network connections, running services, user and domain account information, local group information, and file and directory listings. Observed tradecraft shows the operators reviewing this reconnaissance output to determine whether a victim warranted deeper follow-on activity.
LOWBALL also functioned as a staging mechanism for additional malware. After validating a target, operators could task the implant to retrieve and launch a second-stage backdoor, including BUBBLEWRAP, a more fully featured persistent backdoor. This operational pattern indicates LOWBALL was used as a lightweight cloud-backed backdoor for post-exploitation reconnaissance, command execution, file transfer, and selective deployment of follow-on payloads against targeted Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The spear phishing emails contained three attachments in total, each of which exploited an older vulnerability in Microsoft Office (CVE-2012-0158)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: ipconfig /all >> %temp%\download
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
“3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory… admin@338 actors used… dir c:\ >> %temp%\download … APT28 has used Forfiles to locate PDF, Excel, and Word documents…”
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used post-compromise to gather local network configuration information from infected machines.
Malware used post-compromise to gather local network configuration information via ipconfig.
Backdoor that uses Dropbox as its command-and-control channel.
Malware that uses Dropbox cloud storage for command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.