Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The decoy documents used by the InPage exploits suggest that the targets are likely to be politically or militarily motivated. They contained subjects such as intelligence reports and political situations related to India, the Kashmir region, or terrorism being used as lure documents.
When the malicious .INP file is opened using a vulnerable version of InPage, it will execute the shellcode that is embedded within it... Finally, the shellcode will copy the embedded payload into newly allocated memory before executing it. This newly dropped payload is a DLL...
It proceeds to decrypt an embedded resource object using the RC4 algorithm... Throughout the execution of this sample, numerous strings are decoded using a customized 94-character substitution table... All data received and sent by MY24 is encrypted using a 13-byte XOR key
BioData sends both GET and POST requests to the following URL: http://errorfeedback[.]com/MarkQuality455/developerbuild.php
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Delphi-based backdoor and file stealer used for persistent access and data exfiltration, shared among multiple threat actors including Urpage, Confucius, and Patchwork.
A Delphi backdoor dropped by an InPage exploit. It creates a Document folder under the user profile, establishes persistence via the startup folder, generates a victim identifier, collects username and computer name, beacons to a remote HTTP C2, downloads additional payloads, writes them to disk, and executes them.
A Delphi backdoor dropped by a malicious InPage document. It establishes persistence, generates a victim identifier, collects username and computer name, beacons to a remote C2 over HTTP GET/POST, can download additional payloads, write them to disk, execute them, and notify the operator of execution.
Delphi backdoor that establishes persistence, generates a victim ID, collects username and computer name, beacons to a remote C2 over HTTP GET/POST, can download additional payloads to disk and execute them.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.