Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A name appearing in potentially unwanted software detections involving bundled applications and installers. Historical Microsoft documentation describes startup modifications, browser changes, extensions, process injection and local-proxy behavior. The content explicitly cautions that PUP.Optional.NetFilter, PUA:Win32/NetFilter and App:NetFilterSDK should not be treated as equivalent sample identifications or verdicts. A NetFilter label alone does not establish a rootkit or password stealer, and the legitimate NetFilter SDK is not inherently malware.
A code-signed rootkit mentioned as prior context/comparison for abused signed drivers and rootkits.
NetFilter is a malicious Windows driver (netfilter.sys) that contained a backdoor, signed by Microsoft, and used for post-exploitation persistence and control.
A malicious Windows kernel driver/rootkit with a backdoor added by a third party and signed through the Microsoft OEM program. It is installed during post-exploitation, requires administrative privileges or prior access to install, and is notable for being loaded from atypical locations such as %AppData%.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.