Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le malware Floxif a été injecté directement dans le binaire officiel de CCleaner... Floxif collectait : nom de l’ordinateur, logiciels installés, adresses MAC, identifiant unique de la victime, puis transmettait ces données à un serveur C2.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The disassembler/debugger can’t disassemble the code properly because an ‘EXTRA’ byte has been added after the RETN instruction.
It will delete <filename.DLL.DAT> the next time the system is restarted by using the MoveFileExA API with the parameter NewName=NULL Flags=DELAY_UNTIL_REBOOT.
After hooking the KiUserExceptionDispatcher API, the virus creates a mutex named ‘Global\SYS_E0A9138’
T1497 — Virtualization/Sandbox Evasion (Defense Evasion)
Each module’s path is checked against the three folders whose names were stored earlier: %system%, %windows%, and %temp%. Provided the module is not located in any of the three folders mentioned, the virus will read the file to memory and infect it.
Floxif collectait : ... adresses MAC, identifiant unique de la victime...
Next, it starts enumerating the modules for each process running in the system. Floxif does this by getting the process list using a combination of the CreateToolhelp32Snapshot, Process32First and Process32Next APIs.
Floxif collectait : nom de l’ordinateur, logiciels installés...
After creating the mutex, it stores the names of the %system%, %windows% and %temp% folders using the GetSystemDirectoryA, GetWindowsDirectoryA and GetTempPathA APIs, respectively.
T1497 — Virtualization/Sandbox Evasion (Defense Evasion)
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor embedded in the digitally signed CCleaner 5.33 installer during the 2017 supply-chain compromise. It profiled infected systems and exfiltrated host information to command-and-control infrastructure; a second-stage payload was selectively delivered to a small set of victims based on network-domain names.
Floxif is a Windows virus known for infecting USB devices and spreading via removable media. It has previously been associated with supply chain attacks and can be used to deliver additional payloads or steal information.
Mentioned as one of many malware families observed using .bit domains for C2 infrastructure.
A DLL file infector that infects DLL modules, drops and loads a malicious symsrv.dll component, restores the host DLL in memory so the original code continues to run, and infects additional DLLs in the background. It uses anti-static-analysis tricks to confuse disassemblers and anti-dynamic-analysis by hooking KiUserExceptionDispatcher in ntdll.dll.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.