AuditCred, also known as ROPTIMIZER, is a Windows malware family associated with the Lazarus threat ecosystem. It functions as a remote access capability used in post-compromise operations, providing operators with interactive control over infected systems and support for follow-on payload delivery. Observed behaviors include installation as a new Windows service for persistence, opening a reverse shell to execute commands, downloading additional files and malware, searching folders and files on the host, deleting files, and injecting code from files into other running processes. AuditCred also supports proxy-aware communications and uses XOR and RC4 routines to decrypt code functions during execution, indicating built-in obfuscation and defense-evasion features. Its combination of service-based persistence, process injection, host discovery, command execution, and payload retrieval makes it suitable for sustained intrusion activity and broader post-exploitation objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Similarly, they have been using the set of software below ... S0347 AuditCred
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
AuditCred can utilize proxy for communications... FunnyDream can identify and use configured proxies in a compromised network for C2 communication... Kapeka can identify system proxy settings via WinHttpGetIEProxyConfigForCurrentUser() during initialization and utilize these settings for subsequent command and control operations... PoshC2 contains modules that allow for use of proxies in command and control.
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware capable of injecting code from files into other running processes.
Malware that uses XOR and RC4 to decrypt code functions.
Credential-focused malware/tool that can delete files from the system.
Malware that uses XOR and RC4 to decrypt code functions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.