ShimRatReporter is a Windows malware component focused on automated host reconnaissance and reporting to command-and-control infrastructure. It collects system and user-context information without requiring operator tasking, then compiles the results into reports for transmission to the operators. Observed collection includes running process enumeration, installed software discovery, and detailed local network configuration profiling such as proxy settings, domain information, IP addressing, routing data, MAC address, gateway, DNS servers, and DHCP status. It also uses Windows API functions to gather information from the infected system and has been observed identifying connected UDP endpoints through native API calls. Collected reconnaissance data is compressed with an LZ-based method before transmission and sent to command-and-control servers via HTTP POST requests. The malware has also used masquerading, presenting itself as a benign specialized Unicode font component to reduce suspicion. Overall, ShimRatReporter functions as a reconnaissance-oriented implant or reporting module used for post-compromise host profiling and exfiltration of collected system information over its C2 channel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
"AppleSeed has compressed collected data before exfiltration."; "APT28 used a publicly available tool to gather and compress multiple documents..."; "Aria-body has used ZIP to compress data..."; "Cadelspy...compress stolen data into a .cab file."; "Daserf hides collected data in password-protected .rar archives."; "FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration."; "Lazarus Group has compressed exfiltrated data with RAR...archive specified directories in .zip format"; "XCSSET will compress entire ~/Desktop folders..."
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gathers extensive network and proxy configuration data including IP, routing, MAC, gateway, DNS, and DHCP status.
Malware component that uses Windows APIs to gather information from infected systems.
Malware that spoofs specialized software filenames to appear benign.
Remote access trojan that gathers extensive network configuration data including proxy, domain, IP, routing, MAC, gateway, DNS, and DHCP status.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.