GRAYRABBIT is a custom Windows backdoor associated with the China-linked intrusion set UNC3569 and later observed in related activity clusters including SHADOW-VOID-044 and SHADOW-EARTH-045. It has been identified alongside other UNC3569 tooling such as DRAFTGRAPH and CROSSWALK and is used to provide remote control and post-compromise access on victim systems. Reported tradecraft shows GRAYRABBIT being deployed through staged execution chains that include DLL sideloading and PowerShell-based decoding and in-memory execution, indicating an emphasis on stealth and defense evasion. Infrastructure and tooling overlaps have been used as part of attribution linking some PeckBirdy-enabled campaigns to UNC3569.
UNC3569 has used GRAYRABBIT in broader intrusion operations affecting organizations worldwide, with concentration in East and Southeast Asia and targeting that has included government, education, technology, finance, media, telecommunications, airlines, heavy industry, energy, and the Chinese gambling sector. In observed PeckBirdy-related campaigns, GRAYRABBIT appeared as one of several backdoors delivered or hosted within operations that also used watering-hole compromises, fake browser update lures, and other modular malware. High-confidence reporting supports GRAYRABBIT as a backdoor used for persistent remote access and post-exploitation on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the case of SHADOW-VOID-044, we noticed the GRAYRABBIT backdoor... was hosted on a server operated by this campaign.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
To cover the malicious traffic, the attackers registered C2 domains masquerading as normal AWS or AlibabaCloud domains... This cluster of activity has previously targeted entities... using malicious domains that masquerade as services such as Amazon Web Services and Microsoft Support Services.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor observed on infrastructure tied to SHADOW-VOID-044. The sample used DLL sideloading and UuidFromStringA via PowerShell to read, decode, and execute the payload.
Backdoor found on SHADOW-VOID-044 infrastructure; noted as previously associated with UNC3569.
Backdoor used in the Shadow-Earth-045 activity and previously associated with China-backed UNC3569.
Backdoor previously deployed by UNC3569; observed on infrastructure operated by SHADOW-VOID-044, suggesting possible linkage or shared infrastructure/tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.