Inception is a Windows espionage malware family associated with targeted intrusions and credential theft. It has been observed using a browser-focused plugin to steal saved passwords and active session data from multiple browsers, including Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex, indicating both credential-theft and session-hijacking functionality. Inception also includes reconnaissance capability through a module that enumerates active processes and loaded modules on compromised systems. For command-and-control and data exchange, it has used HTTP, HTTPS, and WebDAV, and its network communications have been protected with AES encryption. Delivery has included luring victims into opening malicious files to initiate reconnaissance and execute malware, consistent with spearphishing-style user-execution tradecraft. The available evidence supports its use in post-compromise collection and operator-controlled intrusion activity against Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Once inside, the handler itself became the training gadget, armed with Inception (CVE-2023-20569) to fill the return stack buffer with an attacker-chosen target. Inception is the 2023 AMD flaw saferet exists to stop.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"...used tasklist to enumerate processes..."; "...used the ps command to list processes..."; "...calling CreateToolhelp32Snapshot... to enumerate the running processes..."
"admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download"; "ADVSTORESHELL can run Systeminfo to gather information about the victim."; "Kimsuky has enumerated drives, OS type, OS version, and other information using a script or the 'systeminfo' command."
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A speculative execution / branch prediction attack technique against AMD processors that can poison return prediction state; here it is used as a component of the interrupt-injection attack chain.
Backdoor with recon module that enumerates processes and loaded modules.
Malware that uses HTTP/HTTPS/WebDAV in network communications (including C2).
Backdoor that used a browser plugin to steal passwords and session data from multiple browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.