arp is a native utility used to display a host's ARP cache, which may contain address resolutions for remote systems on the local network. In the provided content, it is referenced in the context of remote system discovery and network reconnaissance rather than as a standalone malware family. The content specifically notes that arp can be used to display ARP cache entries for remote systems, and that BlackByte used Arp to identify remotely connected devices. Related examples in the same context also note use of ARP-table-based discovery by other malware such as Diavol. No additional malware-specific infection vector, persistence mechanism, payload behavior, or industry targeting is directly provided for arp in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A utility used to inspect ARP cache entries and identify remote systems on a network.
Native utility used to view ARP cache; can support discovery of nearby hosts on a LAN.
Native utility used to inspect ARP cache to identify other hosts on the local network segment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.