Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, it establishes persistence on the system by creating a Scheduled Task named “0BAduEnQZG9POyK”.
the loader proceeds with setting the file attributes of agent.js ... as well as creating the scheduled task named “Firefox Default Browser Agent 458046B0AF4A39CB” via ITaskScheduler interface that runs agent.js file via wscript.exe.
The download batch file “m8hHxtkVLYPw.bat” contains the PowerShell command ... responsible for fetching another payload ... “WLXUL6LWXQPB.js”.
agent1.ps1 ... contains a one-liner command that is responsible for AMSI bypass.
"osascript<<EOD display dialog..."; "uses AppleScript to mute the system’s volume"; "uses AppleScript again... to collect specific files"
The downloaded JavaScript file is responsible for self-replication... it proceeds to retrieve and execute additional payloads via PowerShell commands.
Upon visiting the embedded malicious page that is hosted on Google Sites, we received a CAPTCHA prompt... to receive the payload, the user would have to pass the CAPTCHA prompt first.
The final loader payload is extracted and decrypted using XOR from the resource section, where the XOR key is also located.
For each copied file, it generates a unique GUID as a naming convention. The files are then immediately deleted after their contents have been fully processed.
the program searches for the distinct identifier "LDR," retrieves commands from the C2 server, decodes them from Base64, and decrypts them using XOR with a shared secret as the key.
"osascript<<EOD display dialog ... 'Please enter password' ... with hidden answer"; "prompted the user to install it and grant it Administrator access"
Koi Stealer copies sensitive data, including cookies, history, and login information
"zsh -c mdfind -name .pem"; "SSH configuration files (under $HOME/.ssh)"
retrieves the computer name and name of the currently logged-in user
the infected machine sends another request containing the information gathered from the machine, including OSMajorVersion, OSMinorVersion, OSBuildNumber, Username, ComputerName, and the domain name if present.
The loader further inspects certain directories and files for evidence of a VM environment... performs checks on files with extensions like doc, docx, xls, and xlsx.
Additionally, the loader employs an anti-VM capability. It uses EnumDisplayDevicesW to enumerate display devices... checks for specific files related to VirtualBox... inspects certain directories and files for evidence of a VM environment.
Koi Stealer copies sensitive data, including cookies, history, and login information, to the %AppData% folder.
the infected machine sends another request... The secondary POST request format: 111|{GUID}|{XOR’ed host information}
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a DPRK-attributed macOS stealer whose crypto-wallet targeting list closely matches PHANTOMPULSE reconnaissance.
Stealer malware mentioned as part of overlapping infrastructure tied to ShadowSyndicate-linked nodes.
Infostealer with a newly documented macOS variant; performs host recon and credential capture (including prompting for admin password), steals browser/app/SSH/Keychain/Telegram/Discord/Steam/VPN/FileZilla data and extensive cryptocurrency wallet data, and exfiltrates in two stages to a C2; uses AppleScript for stealth (muting audio, targeted file collection) and runtime string decryption (XOR).
An infostealer delivered by Koi Loader that harvests cookies, browsing history, login data, system information, installed applications, and security software, then compresses, encrypts, and exfiltrates the data to C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.