Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VPN Mentor disclosed CVE-2018-10562 as a GPON command-execution vulnerability. The content provides POST payloads abusing the router diagnostic endpoint to execute wget commands and download Muhstik components. | The attacker utilizes the IP address in Viet Nam and open-sourced Mettle attack module to implant malware; it is the first time the researchers observed this botnet.
VPN Mentor disclosed two vulnerabilities of GPON home routers on 2018-05-01: CVE-2018-10561 authentication bypass and CVE-2018-10562 command execution vulnerabilities. From 2018-05-02 through 2018-05-10, five botnet families were observed using the GPON exploit. | The attacker utilizes the IP address in Viet Nam and open-sourced Mettle attack module to implant malware; it is the first time the researchers observed this botnet.
Linux/Swrort-G (“Mettle”)
13 distinct techniques documented for this family, organized by ATT&CK tactic.
...have been found vulnerable to an authentication bypass (CVE-2018-10561)...
Attackers have been utilizing an open-sourced Mettle attack module to implant malware on vulnerable routers.
Add C2 profile support to win https ... Add support for HTTP/S PHP and TLV config ... Wire MC2 into PHP payloads ... Wire MC2 into mettle | "Working" C2 sessions with diff GET/POST uris ... supports the notion of having different URIs for GET and POST.
Support added and tweaked for including the UUID in an HTTP header or in a GET param. Currently don't have support for it in the BODY as as param, not sure if that's a requirement yet or not. Same goes for cookies.
meterp switched to TLV config. This moves the flags to a TLV instead of the first byte of the config block.
Attackers have been utilizing an open-sourced Mettle attack module to implant malware on vulnerable routers.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stage-two payload delivered by the multi_backupd ELF loader. The content does not describe its post-compromise capabilities.
Named as one of the payloads detected in Log4j exploit attempts.
Mettle is a post-exploitation payload used as part of the Metasploit framework, providing Meterpreter sessions for remote access and control. It is designed to run on low-resource or embedded devices, including iOS and macOS, and allows attackers to interact with compromised systems, execute commands, and pivot within networks.
A botnet family observed exploiting vulnerable GPON routers using an open-sourced attack module to implant malware on the devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.