Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
All the MataDoor samples we discovered were Windows executables and disguised as legitimate programs such as a security solution agent, VPN client, Adobe programs and such.
The actor... examined the network status... cmd.exe /c "netstat -ano | find "TCP"" ... ipconfig /all
Probe TCP connection to specified IP-address:port... Probe TCP connections to IP-subnet:port... ICMP ping all hosts in subnet
Returns following details about all currently running processes... PID, parent PID, command line...
Returns victim ID, configuration settings... and various system information such as Windows version, Processor architecture, Computer name, User name
The new MATA generations incorporate new functionalities... creating a 'stack' of various communication protocols to be used for C2 (Command and Control) communications.
The malware TCP connects to two remote hosts... and then forwards traffic between them... Implements HTTP proxy server... Implements SOCKS4 proxy server
allowing the actor to build complex proxy chains within the victims’ network... Add this victim to a proxy chain.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A rewritten-from-scratch Windows backdoor variant within the MATA family (gen4), typically disguised as legitimate software and often packed with Themida. It runs as a service (e.g., 'wuausrv'), uses encrypted configuration, supports active and passive C2 modes over multiple transports (SSL/DTLS/TCP/UDP), and enables internal proxying/proxy chains and modular plugin-driven capabilities (processes, files, net recon, proxy, inject, monitoring).
A rewritten-from-scratch MATA variant for Windows with modular plugins, passive/active C2 modes, SSL/DTLS/TCP/UDP communications, proxy chaining, process/file/network operations, injection, and monitoring capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.