Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the malware used in these attacks, which we dubbed FakeHMP, was also observed deployed on the machine of an unidentified individual or organization as recently as January 2024.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
In the infection case occurring in 2022, attackers were observed to perform spreading to other machines by using scheduled tasks.
To spread to other machines, attackers uploaded these four files and then created scheduled tasks with the help of the Tpm-HASCertRetr.xml description file.
In the infection case occurring in 2022, attackers were observed to perform spreading to other machines by using scheduled tasks.
In the infection case occurring in 2022, attackers were observed to perform spreading to other machines by using scheduled tasks.
To spread to other machines, attackers uploaded these four files and then created scheduled tasks with the help of the Tpm-HASCertRetr.xml description file.
By placing a malicious DLL at C:\Windows\System32\hmpalert.dll and installing the hmpalert.sys driver, the attackers made the legitimate driver load the malicious DLL into every running process.
Its capabilities included retrieving files from the filesystem... Apart from this implant, we also observed attackers deploying... a file stealer to compromised computers.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FakeHMP is a previously unknown implant used by the Careto threat group, providing surveillance capabilities such as keystroke logging, screenshot capture, file retrieval, and deployment of additional payloads. It leverages legitimate system drivers for stealthy code injection and persistence.
A previously unknown implant delivered via a malicious hmpalert.dll side-loaded through the legitimate HitmanPro Alert driver. It supports file retrieval, keylogging, screenshot capture, and deployment of additional payloads.
A modular implant loaded via the legitimate HitmanPro Alert driver abusing a DLL validation flaw. It injects into winlogon.exe, dwm.exe, and svchost.exe, supports file reading and reflective DLL loading, logs keystrokes, captures screenshots, compresses and AES-encrypts collected data, and exfiltrates it to OneDrive.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.