Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ранее мы рассказывали о вредоносной кампании со шпионским ПО Batavia, жертвами которой стали российские промышленные предприятия.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
winmgmts:\\.\root\cimv2 WMI path used to retrieve OS version and build number
The spyware collects several types of files, including various system logs and office documents found on the computer and removable media.
At the same time as displaying the window, the malware begins collecting information from the infected computer and sends it to an address with a different domain... The newly collected data is sent to https://ru-exchange[.]com/mexchange/?file=2 hc1-[redacted].
104 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Шпионское ПО, используемое в кампаниях Geo Likho для кражи данных. В статье Batavia прямо связывается с предыдущими кампаниями группы; отмечается сходство кода VBE-загрузчиков, функций импланта первого этапа и строк полезной нагрузки. Также ранее наблюдался прием с модификацией идентификатора жертвы по этапам заражения.
Windows spyware used in targeted attacks against Russian organizations; delivered via bait emails with malicious links (per summary).
A newly identified multi-stage spyware campaign that spreads via bait emails containing malicious links to VBE downloaders. It deploys WebView.exe and javav.exe, steals internal documents and system information, collects files from local and removable media, takes screenshots, maintains persistence via a startup shortcut, and can download additional payloads while updating its C2 configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.