PillowMint is a Windows malware family associated with Turla operations and notable for stealthy payload storage and execution from the Windows Registry. It stores a compressed malicious payload in a registry location and uses shellcode to read, decompress, and launch that code without relying on a conventional on-disk executable. The malware has also used PowerShell to install an application compatibility shim database, indicating a persistence mechanism based on shimming. Its execution chain includes shellcode-based staging and use of native Windows APIs for code execution and process injection.
Operationally, PillowMint performs process discovery by repeatedly enumerating running processes, apparently to identify suitable targets for later capture or injection. It also reads registry-based system and network configuration data as part of its command-and-control logic. Reported collection behavior includes theft of payment card data, which is then encrypted with AES and encoded with Base64 prior to exfiltration. Cleanup behavior has included deletion of malware artifacts from disk.
PillowMint fits the pattern of a stealth-focused backdoor used for post-compromise activity on Windows systems, combining registry-resident payload storage, shellcode loaders, PowerShell-assisted persistence, process injection, host reconnaissance, and protected data theft workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Examples include: “ComRAT has encrypted and stored its orchestrator code in the Registry…”, “ShadowPad maintains a configuration block and virtual file system in the Registry.”, and “QakBot can store its configuration information…under HKCU\Software\Microsoft.”
"Gold Dragon encrypts data using Base64..."; "FELIXROOT encrypts collected data with AES and Base64"; "Patchwork encrypted...with AES and then encoded them with base64."; "Pillowmint...encrypted...with AES and further encoded it with Base64."; "Some variants...encode it with base64"; "Zebrocy...hexadecimal for encoding data"
APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as malware that uses similar registry-based storage or execution techniques.
Malware that uses a PowerShell script to install a shim database.
Point-of-sale malware that collects credit card data using native API functions.
Malware that is decompressed by included shellcode before launch.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.