Mivast is a Windows malware family associated with remote shell access, credential harvesting, and Registry-based persistence. It can open a remote shell and execute basic commands on compromised hosts, giving operators interactive post-compromise control. It has also been documented gathering NTLM password information, indicating credential-access functionality focused on Windows authentication material. For persistence, Mivast creates an autostart entry under the Windows Registry Run mechanism so it will execute when the system starts or a user logs on. The available evidence supports classifying Mivast as a remote-access-oriented implant used for post-exploitation on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that establishes persistence by creating an HKLM Run registry entry.
Backdoor malware that persists by creating an HKLM Run registry entry.
Malware capable of gathering NTLM password information (credential theft).
Malware/tool that opens a remote shell and runs basic commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.