SLOTHFULMEDIA is a Windows malware family associated with post-compromise surveillance, host reconnaissance, persistence, defense evasion, and data theft. Documented behavior includes enumerating running processes by process ID, name, and privilege level; collecting the current username; gathering system information; capturing screenshots of the victim desktop; uploading files and host data; and transmitting collected information to command-and-control infrastructure over HTTP and HTTPS POST requests. The malware also supports process injection, indicating use for stealthy execution within other processes.
The malware employs multiple defense-evasion and persistence measures. It has been observed setting itself hidden to reduce user visibility, masquerading under names resembling legitimate executables, modifying Windows Registry settings related to proxy or Internet zone configuration, and creating a Windows service named for persistence. It also performs cleanup and anti-forensic actions by deleting itself and removing browser-history-related artifacts from compromised systems.
Aliases associated with this malware include JackofHearts and QueenofClubs. The observed functionality is consistent with a backdoor-oriented implant used for espionage-style collection and remote operator tasking on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors injecting shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, cmd.exe, lsass.exe, and browser processes.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... SLOTHFULMEDIA ... (v1.0→v1.1) ...
SLOTHFULMEDIA (v1.0→v1.1)
Malware capable of injecting into running processes on a compromised host.
Backdoor that collects the username from a victim machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.