MechaFlounder is a Windows malware family used for command-and-control over HTTP. It profiles compromised hosts by identifying the current username and hostname, and it transmits that victim-identifying information to its command-and-control infrastructure, including embedding the account name and hostname in request data. Its network communications use Base16-encoded strings, indicating a simple obfuscation layer for C2 traffic. MechaFlounder also supports remote command execution on infected systems, making it suitable for post-compromise control and operator tasking. The malware has been observed masquerading as a legitimate Windows process name to reduce suspicion and blend into the host environment. High-confidence reporting supports reconnaissance of host identity, command execution, HTTP-based C2, exfiltration of basic host metadata over the C2 channel, and defense-evasion through masquerading.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Multiple malware families and threat groups are described as collecting the victim username or enumerating logged-on users (e.g., “can collect the username from the victim’s machine”, “enumerates the current user during the initial infection”, “enumerates logged-on users”).
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that identifies the username and hostname on a compromised host.
Identifies the username and hostname on a compromised host.
Malware that sends compromised user account and hostname information to C2.
Malware downloaded under the name of a legitimate Windows process to evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.