Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Loading the page greeted the target with “Video loading please wait ...” The page redirected to a YouTube video a few seconds later, but first loaded a Java exploit [64]—a known vulnerability with no patch at the time that the e-mails were sent. Oracle released a patch 12 hours after activists began receiving these links. | We found a file that VirusTotal had downloaded from faddeha.com, which appeared to be a remote access toolkit known as SpyNet, available for general purchase for 50 Euros.
We found a file that VirusTotal had downloaded from faddeha.com, which appeared to be a remote access toolkit known as SpyNet, available for general purchase for 50 Euros. | In early 2013 UAE H.R. activist E forwarded numerous documents that included a particular CVE-2012-0158 exploit for Microsoft Word. In all, these totaled 17 distinct hashes of documents, and 10 distinct hashes of payloads.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Typically, targets receive either (1) a PE in a .zip or .rar, (2) a file download link, or (3) a link that will trigger a drive-by download.
The exploit loaded shellcode that downloaded a second stage from ar-24.com, which in turn downloaded spyware from ar-24.com.
the spyware payload used a command-and-control server (hamas.sytes.net) linked to attacks believed to be conducted by the UAE government.
We found that the spyware has a modular design, and can download additional modules from a command & control (C&C) server, including password capture...
The attacks often include fake or maliciously packaged security tools; intriguing, or ideological, or movement-relevant content... Researchers and security professionals have already profiled many of these RATs, including DarkComet, Blackshades Remote Controller, Xtreme RAT, njRAT, and ShadowTech.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access toolkit delivered by one of the analyzed exploit documents, suggesting the exploit builder could deploy payloads other than Hacking Team RCS.
Named in leaked file paths as part of the author's working directories, suggesting an environmental or tooling association rather than the main subject of the reference.
Remote access trojan detected in targeted/APT malware telemetry in the reporting period.
Commercial off-the-shelf RAT used in UAE surveillance operations. Delivered through exploit kits and packed droppers, with C2 domains such as hamas.sytes.net.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.