Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Lyceum infection chains are also notable for the fact that they have evolved to drop multiple backdoors since the campaign came to light in 2018 — beginning with DanBot and transitioning to Shark and Milan in 2021 — with attacks detected in August 2021 leveraging a new data collection malware called Marlin.
The Lyceum infection chains are also notable for the fact that they have evolved to drop multiple backdoors since the campaign came to light in 2018 — beginning with DanBot and transitioning to Shark and Milan in 2021 — with attacks detected in August 2021 leveraging a new data collection malware called Marlin.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The ToneDeaf backdoor primarily communicated with its C&C over HTTP/S but included a secondary method, DNS tunneling, which does not function properly," the researchers said. "Shark has similar symptoms, where its primary communication method uses DNS but has a non-functional HTTP/S secondary option. | Marlin makes use of Microsoft's OneDrive API for its C2 operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor attributed to the Lyceum subgroup within OilRig, mentioned as related malware.
Backdoor attributed to OilRig that uses OneDrive API for C2; referenced as a more feature-rich comparator to ODAgent (no full command set provided here).
A newly introduced backdoor/data collection malware used in the long-running Out to Sea espionage campaign. It departs from prior OilRig tradecraft by using Microsoft's OneDrive API for command-and-control operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.