Serpent is a Python-based Windows backdoor used in a targeted espionage-oriented campaign against French government, construction, and real-estate organizations. Initial access relied on French-language, GDPR-themed spearphishing emails carrying macro-enabled Microsoft Word attachments. Enabling macros initiated a multi-stage chain that used steganographically concealed PowerShell and Python payloads and abused the Chocolatey package manager to install Python and required dependencies before loading the backdoor.
Serpent polls attacker-controlled command-and-control infrastructure through a Tor proxy, receives host-specific commands, and executes arbitrary Windows commands on matching infected hosts. It uploads command output to an intermediary service and reports the resulting retrieval reference and host information to a separate command-and-control endpoint. The backdoor supports follow-on payload delivery and reverse-shell access, providing operators broad control of compromised systems. The activity also used scheduled-task-based signed binary proxy execution to reduce visibility of payload execution. The responsible threat actor was assessed as sophisticated but was not attributed to a known group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK TIDs ... T1133 Persistence External Remote Services
TeslaCrypt 4.1b ... used WMIC to delete Shadow Volume Copies from an infected PC... One of [WannaCry's] commands invoked WMIC to delete shadow copies.
Proofpoint says that the backdoor can execute any command sent by the attacks, allowing the threat actors to download further malware, open reverse shells, and gain complete access to the device. | Once loaded, the Serpent backdoor malware will communicate with the attacker's command and control server to receive commands to execute on the infected device.
The PowerShell script will first download and install the Chocolatey Windows package manager, which is then used to install the Python programming language and the PIP package installer
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family reported as abusing WMIC.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Backdoor malware delivered via malicious macro-enabled Word documents. The infection chain uses steganographically embedded payloads in JPG files, PowerShell to install Chocolatey and Python, then executes Python scripts that beacon to Tor proxy C2 infrastructure, run attacker commands, and exfiltrate results via Termbin URLs.
A Python-based backdoor delivered through a multi-stage phishing chain using malicious Word macros, steganographic images, and Chocolatey-installed Python components. Once loaded, it communicates with a command-and-control server, executes attacker commands, enables reverse shells, downloads additional malware, and provides full access to the infected device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.