Magic Hound is malware associated in the provided content with host reconnaissance, collection, and command-and-control activity. Reported capabilities include obtaining the victim username and sending it to the C2 server; gathering the victim’s local IP address, MAC address, and external IP address; listing running processes; taking screenshots and uploading them to its C2 server; and determining whether the C2 server wants a newly dropped file executed in a hidden window. The malware has used HTTP for C2 communications. Based on the provided content, its observed behavior is consistent with a backdoor or RAT used for victim profiling, surveillance, and follow-on payload execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple malware and threat groups are described as collecting the current username or user/session details, frequently via built-in OS commands/APIs (e.g., "whoami", "query user", "quser", GetUserNameA) and via WMI/PowerShell.
"...used tasklist to enumerate processes..."; "...used the ps command to list processes..."; "...calling CreateToolhelp32Snapshot... to enumerate the running processes..."
Multiple malware families and threat groups are described as collecting the victim username or enumerating logged-on users (e.g., “can collect the username from the victim’s machine”, “enumerates the current user during the initial infection”, “enumerates logged-on users”).
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware capable of enumerating running processes for reconnaissance.
Malware observed using HTTP for command-and-control (C2).
Malware that captures screenshots and uploads them to C2.
Malware that collects local IP, MAC, and external IP address information from victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.