Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This second stage payload utilizes a well-known vulnerability in a VirtualBox driver (CVE-2008-3431) to load the third stage, which is designed to run in kernel mode.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June 2020, Unit42 identified the ACIDBox malware.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The next stage payload, ‘oxygen.dll’, is built with the same compiler (Microsoft Visual C/C++ 2013) and linker (Microsoft Linker 12.0), and meant to be decrypted in order to inject into a target process via reflective loading.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AcidBox is referenced as malware using malicious drivers and rootkit functionality, including service-based loading for persistence and concealment.
Malware discussed in the context of attribution pitfalls caused by misleading code similarities.
A newly discovered malware/activity cluster discussed as potentially related to Remsec or Turla tradecraft. The referenced sample is a DLL, with a next-stage payload ('oxygen.dll') that is decrypted and reflectively loaded into a target process for injection.
Rare, targeted modular Windows malware (2017) that uses SSP DLLs for injection/persistence (loading into lsass.exe), stores its main worker and additional payloads encrypted in the registry, and leverages a VirtualBox VBoxDrv.sys driver exploit to disable Driver Signature Enforcement and load an unsigned kernel-mode payload driver. Uses steganography (encrypted/zlib-compressed overlays in icon resources) and multiple encryption layers (XOR for registry blob; RSA for embedded driver).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.