RICECURRY is a JavaScript-based profiler used by APT37 in strategic web compromise and watering hole operations. Its documented role is to profile a victim's web browser and deliver malicious code accordingly. The provided content associates RICECURRY specifically with APT37 campaigns involving compromised websites, particularly South Korean websites, as part of web-based initial access activity. High-confidence behavioral detail in the source is limited to browser profiling and conditional malicious code delivery; no additional infection chain details, targeted industries, or specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript-based browser profiler used during strategic web compromise to fingerprint victims and tailor delivery of malicious code.
A JavaScript-based browser profiling tool used in watering-hole/strategic web compromise activity to fingerprint victims' browsers and tailor delivery of malicious code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.