Megatools is a command-line client for the Mega.nz cloud storage service that has been used by threat actors for data exfiltration. In the provided reporting, it was used to upload stolen data to Mega, including a RAR archive named sig.rar. Symantec reported its use by the North Korea-linked Stonefly group, also tracked as Andariel, APT45, Silent Chollima, and Onyx Sleet, during financially motivated intrusions against U.S. private companies observed in August 2024. In those intrusions, Megatools was part of a broader toolset that included credential theft, keylogging, tunneling, discovery, and backdoor activity. Mandiant also identified binaries configured to upload data to Mega in suspected Russian intrusion activity associated with UNC2452/Nobelium and later merged with APT29 attribution; in that case the tool was deployed as mt.exe and mtt.exe, though Mandiant noted the Megatools binary appeared to fail when renamed, so exfiltration success was unclear. High-confidence indicators directly mentioned in the content include use of Mega cloud storage for exfiltration, the uploaded file name sig.rar, and renamed Megatools binaries mt.exe and mtt.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Megatools: A command line client for the Mega.nz cloud storage service. Megatools was used to perform data exfiltration
Mandiant identified binaries that were configured to upload data to the Mega cloud storage provider... it appears that the Megatools binary used by the threat actors fails to execute if renamed.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.