Out1 is malware associated with host-based data collection, particularly the harvesting of email content and local system information. Reported functionality includes parsing emails on a target machine and copying files and Windows Registry data from compromised hosts. These behaviors indicate use in post-compromise collection activity, where the malware is used to gather potentially sensitive user and system data for operator review or later exfiltration. Available information supports Out1 as a Windows-focused malware family or tool used for collection from infected endpoints, but does not establish a specific delivery mechanism, threat actor attribution, or a more specialized malware class with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that copies files and registry data from compromised hosts.
Tool/malware component that parses emails on a compromised host.
Malware/tool that can parse emails on a compromised host.
Malware capable of copying files and Windows Registry data from compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.