Koadic, also known as COM Command & Control, is an open-source Windows post-exploitation framework and remote-access tool. Its server component is written in Python, while its agents use JScript and VBScript executed primarily through Windows Script Host. Koadic supports command execution, shellcode execution, reflective DLL-based process injection, user and domain-session discovery, routing-table and Windows-domain discovery, and local SMB scanning. It can transfer files from compromised hosts to its command-and-control infrastructure, execute additional payloads through signed Windows utilities including Regsvr32, Mshta, and Rundll32, and establish persistence through PowerShell, scheduled tasks, Registry Run keys, and WMI event subscriptions. It can bypass UAC through Event Viewer and sdclt-based methods, and may hide PowerShell execution windows. Koadic has been used by threat actors and intrusion campaigns including MuddyWater and ChessMaster, and has also appeared in ransomware-affiliate post-compromise toolsets. It targets Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 (patched in September 2017) within the Microsoft .NET framework to download additional malware. | ChessMaster can utilize any of these methods to download the next malware in the chain, the open source post-exploitation tool known as “Koadic,” which the previous campaign also used.
While ChessMaster still uses the previous exploit, it also added more methods to its arsenal: one exploits another vulnerability, CVE-2017-11882 (patched in November 2017), which was also exploited to deliver illegal versions of the Loki infostealer. | ChessMaster can utilize any of these methods to download the next malware in the chain, the open source post-exploitation tool known as “Koadic,” which the previous campaign also used.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.
Since the emergence of MuddyWater, we found that its operators used multiple open source post-exploitation tools... Koadic
ChessMaster can utilize any of these methods to download the next malware in the chain, the open source post-exploitation tool known as “Koadic,” which the previous campaign also used.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
UNC2198 has used Cobalt Strike BEACON, Metasploit METERPRETER, KOADIC, and PowerShell EMPIRE offensive security tools during this phase as well.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution matrix 2 Technique Count Frameworks WMI 1/10 • Koadic
Persistence matrix 1 Technique Count Frameworks Scheduled Task/Job 7/10
Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.
Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 ... While ChessMaster still uses the previous exploit, it also added more methods to its arsenal: one exploits another vulnerability, CVE-2017-11882...
Persistence matrix 1 Technique Count Frameworks Scheduled Task/Job 7/10
Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.
Persistence matrix 1 Technique Count Frameworks Scheduled Task/Job 7/10
Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Persistence matrix 2 Technique Count Framework WMI Event Subscription 4/10
Persistence matrix 1 Technique Count Frameworks Registry Run Key/Startup Folder 9/10
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory.
For NOBELIUM, the beaconing transform catches the offending process, rundll32.exe, as well as the two destination IPs...
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
{Variable}.user.DC Get DCName from Registry ... {Variable}.registry.read Get/Read Registry Entries
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
APT41 used the WMIEXEC utility to execute whoami commands on remote machines; FIN10 used Meterpreter to enumerate users on remote systems; Operation Wocao enumerated sessions and users on a remote host.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Some of the common protocols used for C2 are HTTP/S, DNS, SSH, and SMTP, as well as common cloud services like Google, Twitter, Dropbox, etc. Using common protocols and services for C2 allows adversaries to masquerade as normal network traffic and hence evade firewalls.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
82 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access/post-exploitation tool previously distributed via SocGholish.
Named malware/tool family deployed via SocGholish.
Backdoor/post-exploitation malware that hides PowerShell execution windows.
Post-exploitation framework/RAT associated with using multiple taskhost.exe/taskhostex.exe processes to support discovery and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.