Splinter is a Rust-based Windows post-exploitation implant and red-team tool that has been observed on multiple victim systems. It operates as a task-driven implant configured through embedded JSON data and communicates with an operator-controlled command-and-control server over HTTPS using authenticated sessions. Known functionality includes execution of Windows commands, bidirectional file transfer, remote process injection for module execution, collection of cloud account information, and self-deletion. Its process-injection workflow includes creating a thread in a remote process to run PE-loading shellcode and execute a payload.
Splinter has been observed as both executable and DLL variants and appears designed for use after initial compromise rather than as a standalone intrusion vector. Public reporting did not attribute its development or operational use to a specific threat actor with confidence. Separate reporting has noted a stage-two payload named Splinter within a BitterAPT activity cluster, but attribution of the broader toolset remains uncertain. The malware is notable because, although presented as a red-team capability, its feature set is fully suitable for malicious post-compromise operations in enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Splinter uses the classic process injection method as an option for running additional modules. Figure 1 shows thread creation in a remote process that runs a PE loader shellcode that in turn executes the payload.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Splinter is a Rust-based post-exploitation red team tool/implant that connects to an HTTPS C2 server using embedded credentials, receives tasks from the server, executes Windows commands, performs remote process injection to run additional modules, uploads and downloads files, gathers information from a cloud service account, and can self-delete.
Stage-2 payload used by BitterAPT in the TurtlePower campaign.
Splinter is referenced as malware detected via the VirTool:Win32/SPLINTER.A!MTB signature/behavior, which is described as scanning memory to identify the presence of the Splinter threat.
Splinter is referenced as malware detected via a behavior-based method (Behavior:Win32/Splinter.A!sms) that scans memory to identify the presence of the threat.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.