Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
C2 domains are retrieved by downloading and base64-decoding the trailing bytes appended to icon files staged in the IconStorages Github repository.
The ffmpeg.dll binary extracts SUDDENICON from d3dcompiler_47.dll by seeking the FEEDFACE byte sequence and decrypting using a static RC4 key.
C2 domains are retrieved by downloading and base64-decoding the trailing bytes appended to icon files staged in the IconStorages Github repository.
After initially connecting to an active C2 server, the malware performs a POST containing a machine identifier.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoored component delivered via a trojanized 3CXDesktopApp supply-chain update. It is extracted/decrypted from a DLL (d3dcompiler_47.dll) by another DLL (ffmpeg.dll) using RC4, loaded in-memory with a shellcode stub, delays execution ~7 days via a dropped 'manifest' file/timer, retrieves C2 domains from GitHub-hosted icon files (base64-decoded trailing bytes), posts a machine identifier to C2, then downloads/decrypts an additional executable (noted as likely an infostealer).
A second-stage payload delivered through the compromised 3CXDesktopApp supply chain. It is extracted and RC4-decrypted by the trojanized ffmpeg.dll, memory-mapped via shellcode, delays C2 activity for seven days, obtains C2 domains from encoded data appended to icon files, posts a machine identifier, and downloads/decrypts a further executable initially assessed as an information stealer.
Mentioned only in references as prior related research.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.