RARSTONE is malware that uses SSL to encrypt communications with its command-and-control (C2) server. It can download a DLL from its C2 infrastructure and load that DLL into the memory space of a hidden Internet Explorer process, indicating in-memory execution and process injection into iexplore.exe for stealth. Based on the provided content, high-confidence behavior includes encrypted C2 over SSL and delivery/execution of a DLL payload within a concealed browser process. No specific threat actor, infection vector, targeted industry, or indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Decrypts in memory, downloads a DLL from C2, and loads it into a hidden Internet Explorer process without dropping it to disk.
Malware that uses SSL to encrypt communications with its C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.