Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareExploits 1 CVE

Agent

Agent is a generic malware/tool name used in multiple distinct contexts in the provided content rather than a single well-defined family. High-confidence references include: (1) Trojan-Downloader.AndroidOS.Agent.no, embedded in modified messaging apps and other Android app mods, which downloads Trojan-Clicker.AndroidOS.Agent.bl; the clicker opens ad URLs in an invisible WebView and uses machine learning to locate and click close buttons, inflating ad views on victims’ devices. (2) Trojan.Loader.Agent, a detection name for a malicious DLL in a multi-stage Windows loader campaign delivered via phishing emails impersonating a travel agency. That campaign abused CVE-2013-3900 to trojanize a signed WinWord.exe, side-loaded msvcr100.dll, established persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run and a scheduled task named WindowsUpdateCore, decrypted a payload hidden in the certificate area, and hollowed cvtres.exe to launch a RAT. Reported capabilities of the final payload included TLS-encrypted C2, screen capture, WMI-based host reconnaissance, file theft, active-window tracking, idle-time-based keylogging activity, privilege checks, runtime code execution, and downloading additional modules stored in the registry; reported IOCs included MD5 6CC1EAD08ADD4F967370FF1D6D07F9E1, MD5 C4C6B65C8D32B27B737E7E95ECC00D69, C2 104.37.173.244:56001, and mutexes WUCorePayload_4A8F and Ethatqehl. (3) An OS X malware context tied to CoinThief, where a RAT-like binary named Agent was installed at ~/Library/Application Support/.com.google.softwareUpdateAgent after delivery via trojanized applications such as StealthBit; it appeared responsible for sending data to remote servers and enabling remote access, and checked for Little Snitch and 1Password. (4) During Operation Wocao, threat actors used a custom proxy tool called Agent that supported multiple hops, encrypted hop IP addresses with RC4, and upgraded sockets to TLS to relay traffic. Because the content conflates several unrelated Android, Windows, macOS, and intrusion-tool usages under the same label, Agent should be treated as an ambiguous/generic name rather than a single malware family.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2013-3900Microsoft Authenticode WinVerifyTrust signature verification bypass in PE files

IoC 표에서 악성 DLL 파일의 탐지명으로 'Trojan.Loader.Agent'가 제시되며, 전체 공격은 다단계 로더를 통해 최종 원격 제어 및 정보 탈취 모듈을 실행하는 구조로 설명됩니다.

via alyac blogblog.alyac.co.kr
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1053.005Scheduled TaskEvidence1

If Handsoff is not installed the backdoor will be made persistent by creating a fake Googe Software Update launch agent.

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

If Handsoff is not installed the backdoor will be made persistent by creating a fake Googe Software Update launch agent.

Privilege Escalation

1 technique
T1053.005Scheduled TaskEvidence1

If Handsoff is not installed the backdoor will be made persistent by creating a fake Googe Software Update launch agent.

Credential Access

1 technique
T1056Input CaptureEvidence2

Среди вредоносного ПО для мобильных устройств самой распространенной угрозой стали троянцы класса Trojan-Banker... Наиболее активными банковскими троянцами стали варианты Mamont (73,5%).

Discovery

1 technique
T1518Software DiscoveryEvidence1

There is a method that verifies the presence of Little Snitch... There’s also a method checking for 1Password.

Collection

1 technique
T1056Input CaptureEvidence2

Среди вредоносного ПО для мобильных устройств самой распространенной угрозой стали троянцы класса Trojan-Banker... Наиболее активными банковскими троянцами стали варианты Mamont (73,5%).

Command and Control

4 techniques
T1071.001Web ProtocolsEvidence1

What it does is to try to contact a remote server and download a file... $.get( settings.get('reportServer') + "/updates/firstUpdate.php" ... )

T1090ProxyEvidence1

Gomir uses reverse proxy functionality that employs SSL to encrypt communications. During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket.

T1090.001Internal ProxyEvidence1

"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."

T1090.003Multi-hop ProxyEvidence4

"During Operation Wocao, threat actors used a custom proxy tool called 'Agent' which has support for multiple hops." / "Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

Agent | Mallory