RDFSNIFFER is a Windows malware family documented as interacting extensively with victim systems through Win32 API functions. Observed behavior includes deletion of local files on compromised hosts, indicating a defense-evasion and cleanup capability that can be used to remove artifacts, operational data, or traces of activity. Available reporting supports its operation on Windows systems but does not provide sufficient high-confidence detail to classify it more specifically by malware family, nor to attribute it to a particular threat actor or confirm distinct delivery vectors from the supplied facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that uses several Win32 APIs to interact with victim systems.
Credential theft malware with local file deletion capability.
Interacts with victim machine using Win32 APIs (details not specified).
Interacts with the victim machine using multiple Win32 API functions (details not specified).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.