CARROTBALL is malware associated with email-based social engineering in which victims are lured into opening malicious attachments to trigger execution. Reported activity indicates it relies on user interaction as the primary execution mechanism, consistent with phishing-delivered malware that depends on a recipient opening an attached file rather than exploiting a vulnerability automatically. High-confidence reporting in the available data supports malicious email attachments as its observed delivery vector, but does not provide sufficient corroborated detail to classify its payload family more specifically, nor to attribute additional capabilities, targeted sectors, or platform scope with confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware executed when users open malicious email attachments.
Malware executed through malicious email attachments.
Malware executed through malicious email attachments.
CARROTBALL has been executed through users being lured into opening malicious e-mail attachments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.