down_new is a Windows malware family associated with the TICK espionage group, also known as BRONZE BUTLER and REDBALDKNIGHT. It emerged in the Operation ENDTRADE intrusion set as part of TICK’s continued malware development targeting organizations in Japan and related subsidiaries in China, particularly in the defense, aerospace, chemical, and satellite sectors.
The malware functions as a backdoor-oriented implant used after compromise for host profiling, command-and-control, and persistence. Reported capabilities include enumerating running processes, detecting antivirus products and security-related processes, collecting host identifiers such as MAC address and volume information, and gathering information about installed applications. It also supports encrypted and encoded command-and-control traffic, specifically using AES encryption together with Base64 encoding, reflecting an emphasis on stealth and traffic obfuscation.
Operationally, down_new has been observed adding autorun persistence on Windows systems and using legitimate websites as command-and-control relays. Samples were configured to execute only during working hours, indicating operator tradecraft intended to blend malicious activity with normal enterprise usage patterns and reduce detection. The malware family was described as incorporating features from earlier TICK tooling and evolving through iterative development and testing.
Within TICK operations, down_new formed part of a broader espionage toolkit that included other malware such as DATPER, Avenger, and Casper. These campaigns relied on compromised legitimate email accounts and spearphishing lures to gain access, after which implants such as down_new supported reconnaissance, defense evasion, and sustained access in victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
down_new This malware combines features of existing trojans in the malware family’s development, based on the adjustments TICK made as we analyzed their test versions.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Executes only during working hours (8:00AM-6:00PM, using kernel32.GetLocalTime API)
"Bazar can query the Registry for installed applications"; "Dridex has collected a list of installed software on the system"; "Tropic Trooper's backdoor could list the infected system's installed software"; "Windigo has used a script to detect installed software"
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identifies MAC addresses of compromised hosts.
Backdoor that identifies the MAC address of compromised hosts.
Backdoor capable of AES-encrypting C2 communications.
Malware capable of listing running processes on a compromised host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.