TROJ_GETVERSION is malware associated with the BRONZE BUTLER threat actor. The provided content states that BRONZE BUTLER used TROJ_GETVERSION to discover system services on compromised Windows systems. This places the malware in post-compromise discovery activity focused on enumerating services to understand the victim environment and support follow-on actions. No additional high-confidence details about infection vector, persistence, broader capabilities, targeted industries, or specific indicators of compromise are provided in the content beyond its use for system service discovery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan used to discover/enumerate system services on compromised hosts.
Trojan used to discover/enumerate system services on compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.