BlackMould is a native web shell for Microsoft IIS servers that has been associated with the China-aligned intrusion set GALLIUM and is described as being based on China Chopper. It is used as a server-side post-compromise access mechanism that enables operators to maintain control of compromised web servers, execute commands, and transfer files over web protocols. Reported functionality includes enumerating local drives and storage, discovering files and directories, copying files on the host, downloading files to the victim system, exfiltrating files from the server, setting file attributes, and executing commands through the Windows command shell. Its command-and-control traffic has been observed using HTTP POST requests. BlackMould has been used in espionage-oriented intrusions, particularly against strategically relevant organizations, and has appeared in activity attributed to GALLIUM, a threat actor known for targeting telecommunications providers as well as government and financial-sector entities. As an IIS-resident web shell, BlackMould is primarily a Windows server threat and serves as a lightweight persistence and post-exploitation tool for follow-on collection and remote administration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GALLIUM ... Examples of associated tools: PlugX, ChinaChopper, Poison Ivy, HTRAN, Mimikatz, NBTscan, Netcat, PsExec, BlackMould...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
This tool can be used by the attackers for a variety of purposes and tasks including enumerating local drives, performing basic file operations, setting file attributes, exfiltrating and dropping files, and running malicious commands on compromised devices.
GALLIUM relies on web shells to gain persistence within a target's network and to drop their second stage malware payloads... In addition to standard China Chopper, GALLIUM has been observed using a native web shell for servers running Microsoft IIS that is based on the China Chopper web shell, a web shell Microsoft dubbed BlackMould.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BlackMould is a webshell for Microsoft IIS servers, based on China Chopper, used for remote access and persistence.
Malware that can copy files on compromised hosts.
A native IIS web shell based on China Chopper, used for persistence and to drop second-stage payloads. It can enumerate drives, perform file operations, set file attributes, exfiltrate and drop files, and execute commands on compromised systems.
Malware capable of downloading files to victim machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.