Agent is a highly ambiguous malware designation that has been used across multiple unrelated malware detections and tools rather than a single well-defined family. The name appears in Android detection labels for spyware, banking trojans, downloaders, and clickers; in Windows detections for loader activity; in macOS analysis as the name of a RAT-like component associated with CoinThief; and as the name of a custom multi-hop proxy utility used during Operation Wocao. Because these references span distinct platforms, behaviors, and intrusion roles, “Agent” is best understood as a generic or vendor-specific naming convention unless additional context identifies the exact sample or family.
Documented uses of the name include Android malware involved in banking fraud and spyware activity, downloader-to-clicker chains embedded in modified applications, a Windows multi-stage loader that used DLL sideloading, persistence, and process hollowing to launch a remote-access payload, a macOS component associated with cryptocurrency theft and remote access in CoinThief infections, and a custom proxy tool that supported encrypted multi-hop communications for post-compromise operations. Depending on the specific context, capabilities attributed to malware labeled Agent have included credential theft, keylogging-related activity, exfiltration, persistence, remote command execution, defense evasion, and proxying for lateral or covert operator access.
No single malware class can be assigned with high confidence to the name alone, and any precise classification requires the surrounding platform, detection name, campaign, or actor context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
IoC 표에서 악성 DLL 파일의 탐지명으로 'Trojan.Loader.Agent'가 제시되며, 전체 공격은 다단계 로더를 통해 최종 원격 제어 및 정보 탈취 모듈을 실행하는 구조로 설명됩니다.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Techniques ... Command and Control App Layer Protocol (Web) T1071.001 Controls operation through web-based dashboard; Sends results back to central server
Gomir uses reverse proxy functionality that employs SSL to encrypt communications. During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware family represented in the report by both spyware and banking trojan variants.
Android malware family represented in both trojan-spy and banking trojan detections in the report.
Android malware family appearing in both spyware and banking trojan detections, with several variants ranking among top mobile banking threats.
A compiled Go binary used as persistent access and orchestration tooling, turning compromised devices into remote command-execution points for repeatable access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.