Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Privilege Escalation T1068 Exploitation for Privilege Escalation Группа Space Pirates может использовать уязвимость CVE-2017-0213 для повышения привилегий
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BH_A006 имеет нетривиальную схему исполнения полезной нагрузки, которая может варьироваться на начальных этапах в различных экземплярах.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
инжектор ... сводится к извлечению DLL следующей стадии и внедрению ее кода в процесс rdpclip.exe... ВПО группы Space Pirates может внедрять шеллкод в другие процессы
Одна из стадий ВПО BH_A006 обфусцирована с помощью неизвестного протектора
При создании сервисов группа Space Pirates использует легитимно выглядящие имена
Группа Space Pirates маскирует свое ВПО под легитимное ПО
инжектор ... сводится к извлечению DLL следующей стадии и внедрению ее кода в процесс rdpclip.exe... ВПО группы Space Pirates может внедрять шеллкод в другие процессы
ВПО группы Space Pirates шифрует конфигурационные данные и полезную нагрузку с помощью различных алгоритмов
Группа Space Pirates может использовать rundll32.exe для запуска DLL-библиотек
73 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage loader culminating in a Gh0st-derived backdoor payload. Uses layered droppers/loaders (overlay DLL reflective load; Sandboxie side-loading; encrypted .dat shellcode stages; repeated MemLoadLibrary-style reflective loading). Implements UAC bypass paths and persistence/service creation; includes a distinctive network signature generation algorithm (bit-level encoding with constant 0x31230C0). Shares shellcode/loader techniques with 9002 RAT samples.
Многостадийный загрузчик и бэкдор на основе модифицированного Gh0st, использующий несколько стадий шеллкода, обход UAC, side-loading и обфускацию для запуска полезной нагрузки.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.