Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Blitz has been distributed in two campaigns. The first campaign spread Blitz through software packages pretending to be cracked installers for legitimate programs. The latest version of Blitz from the second campaign was distributed through game cheat packages named Elysium_CrackBy@sw1zzx_dev.zip and Nerest_CrackBy@sw1zzx_dev.zip.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
After downloading and storing the Blitz downloader as %localappdata%\Microsoft\Internet Explorer\ieapfltr.dll, the backdoored cheat creates a logon script entry in the Windows registry for persistence at HKCU\Environment named UserInitMprLogonScript.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
After downloading and storing the Blitz downloader as %localappdata%\Microsoft\Internet Explorer\ieapfltr.dll, the backdoored cheat creates a logon script entry in the Windows registry for persistence at HKCU\Environment named UserInitMprLogonScript.
Finally, the Blitz downloader checks whether the Windows application RuntimeBroker.exe is running, so it can inject the downloaded Blitz bot payload into the process... This C2 endpoint returns the Monero (XMR) cryptocurrency miner binary, which the bot injects into explorer.exe.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
The malware's binaries are packed with UPX, reducing their size and altering their signature to evade traditional malware detection.
The cheat then decrypts various XOR-encrypted API function strings... It dynamically resolves these functions... When the persistence method executes this function, the downloader decrypts a list of API function strings and dynamically resolves them.
Finally, the Blitz downloader checks whether the Windows application RuntimeBroker.exe is running, so it can inject the downloaded Blitz bot payload into the process... This C2 endpoint returns the Monero (XMR) cryptocurrency miner binary, which the bot injects into explorer.exe.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
The backdoored cheat uses an anti-sandbox check before downloading the malware’s next stage... The backdoored Elysium cheat executes more anti-sandbox checks... terminate if it detects one of the following conditions in its environment: The number of processors is fewer than four, The screen resolution matches specific low values, The ANY.RUN device driver exists, Known sandbox and virtual environment registry values/keys exist.
Blitz bot performs information-stealing functions like keylogging... Afterwards, Blitz bot starts its keylogging function. The keylogging function constantly writes the logged keystrokes, program name and log time into a file %temp%\RestartManager.log.
Once access is gained, it executes system reconnaissance commands, collecting user privileges.
The malware scans the local subnet of newly compromised systems, identifying additional SSH-accessible machines to attack.
The malware executes various commands to collect details about the system’s CPU, user privileges, operating system, memory usage, and available binaries.
As the function names in Figure 16 show, Blitz bot has the following functionality: Downloading/uploading files... cd Expand the environment-variable strings with the one followed after the command cd and set it as the current directory.
The backdoored cheat uses an anti-sandbox check before downloading the malware’s next stage... The backdoored Elysium cheat executes more anti-sandbox checks... terminate if it detects one of the following conditions in its environment: The number of processors is fewer than four, The screen resolution matches specific low values, The ANY.RUN device driver exists, Known sandbox and virtual environment registry values/keys exist.
Blitz bot performs information-stealing functions like keylogging... Afterwards, Blitz bot starts its keylogging function. The keylogging function constantly writes the logged keystrokes, program name and log time into a file %temp%\RestartManager.log.
Blitz bot encodes the current work directory value as a Base64 string and converts the victim's Windows user account name to a hexadecimal string.
99 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Blitz is a trojan malware, with a new version being distributed via backdoored game cheats.
Windows malware with two stages: a downloader and a bot payload. The bot provides attacker control of infected hosts, performs keylogging, screenshot capture, file upload/download, code injection, and can execute denial-of-service requests against web servers. It was distributed via trojanized/cracked software and backdoored game cheats, used Hugging Face Spaces for payload hosting and C2, and also deployed a Monero miner as follow-on malware.
Custom SSH brute-force component used by OUTLAW to retrieve targets and credentials from C2, compromise hosts, change passwords, profile systems, exfiltrate host data, scan local subnets, and transfer the malware package directly to new victims.
Custom multi-threaded SSH brute-force component that retrieves target and credential lists from C2, profiles successfully accessed hosts, changes account passwords, exfiltrates host and credential data, scans local subnets, and transfers the OUTLAW package to newly compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.