Matroyshka is a Windows malware family with remote-access and surveillance functionality. Observed capabilities include keylogging, screen capture, and provision of Meterpreter shell access, indicating use for interactive post-compromise control and victim monitoring. It establishes persistence through multiple Windows mechanisms, including a Registry Run key that launches code via rundll32.exe and a scheduled task masquerading as a legitimate Microsoft component. The use of rundll32.exe suggests an effort to blend malicious execution with trusted Windows binaries and reduce detection. The combination of credential-collection-adjacent monitoring, screenshot capture, remote shell enablement, and durable persistence is consistent with a backdoor or RAT used after initial compromise to maintain access and support follow-on operations against Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples throughout the content include: "APT29 used named and hijacked scheduled tasks to establish persistence"; "APT3 downloader creates persistence by creating the following scheduled task: schtasks /create ... /sc ONLOGON"; "Shamoon ... scheduling an unnamed task to execute the malware"; "menuPass ... execute a command on a target machine via Task Scheduler."
Examples throughout the content include: "APT29 used named and hijacked scheduled tasks to establish persistence"; "APT3 downloader creates persistence by creating the following scheduled task: schtasks /create ... /sc ONLOGON"; "Shamoon ... scheduling an unnamed task to execute the malware"; "menuPass ... execute a command on a target machine via Task Scheduler."
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Examples throughout the content include: "APT29 used named and hijacked scheduled tasks to establish persistence"; "APT3 downloader creates persistence by creating the following scheduled task: schtasks /create ... /sc ONLOGON"; "Shamoon ... scheduling an unnamed task to execute the malware"; "menuPass ... execute a command on a target machine via Task Scheduler."
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware capable of performing screen captures.
Malware capable of keylogging.
Malware capable of providing Meterpreter shell access.
Malware using rundll32.exe in Run key persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.