Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

Koalemos

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1587.001MalwareEvidence1

the threat actors are said to have asked candidates to clone a GitHub repository and run commands to install an npm package to trigger malware execution.

Initial Access

2 techniques
T1195Supply Chain CompromiseEvidence1

Another variant of the intrusion set documented by Panther is suspected to involve the use of malicious npm packages to deploy a modular JavaScript remote access trojan (RAT) framework dubbed Koalemos via a loader.

T1566.002Spearphishing LinkEvidence1

The malicious phase of the attack kicks in when individuals presenting themselves as recruiters and hiring managers instruct targets to complete a skill assessment that eventually leads to them executing malicious code.

Execution

2 techniques
T1059.007JavaScriptEvidence1

using malicious Microsoft VS Code task files to execute JavaScript malware disguised as web fonts

T1204User ExecutionEvidence1

the threat actors are said to have asked candidates to clone a GitHub repository and run commands to install an npm package to trigger malware execution.

Stealth

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

The initial loader performs DNS-based execution gating and engagement date validation before downloading and spawning the RAT module as a detached process.

Discovery

4 techniques
T1033System Owner/User DiscoveryEvidence1

It supports 12 different commands to conduct filesystem operations, transfer files, run discovery instructions (e.g., whoami), and execute arbitrary code.

T1082System Information DiscoveryEvidence1

Koalemos performs system fingerprinting, establishes encrypted command-and-control communications, and provides full remote access capabilities.

T1083File and Directory DiscoveryEvidence1

It supports 12 different commands to conduct filesystem operations, transfer files, run discovery instructions (e.g., whoami), and execute arbitrary code.

T1497Virtualization/Sandbox EvasionEvidence1

The initial loader performs DNS-based execution gating and engagement date validation before downloading and spawning the RAT module as a detached process.

Collection

1 technique
T1005Data from Local SystemEvidence1

The end goal of these efforts is two-pronged: to generate a steady revenue stream to fund the nation's weapons programs, conduct espionage by stealing sensitive data

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence1

The RAT is designed to enter a beacon loop to retrieve tasks from an external server, execute them, send encrypted responses, and sleep for a random time interval before repeating again.

T1105Ingress Tool TransferEvidence1

Running the setup process resulted in malware being downloaded and executed on the victim's system, giving the attackers a foothold in the victim's machine.

T1219Remote Access ToolsEvidence1

Another variant of the intrusion set documented by Panther is suspected to involve the use of malicious npm packages to deploy a modular JavaScript remote access trojan (RAT) framework dubbed Koalemos via a loader.

T1573Encrypted ChannelEvidence1

Koalemos performs system fingerprinting, establishes encrypted command-and-control communications, and provides full remote access capabilities.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.