Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
creates persistence and injects code into a signed Windows binary before security monitoring initializes.
The Python source code points to a targeted operation. It impersonates a DBeaver installer
creates persistence and injects code into a signed Windows binary before security monitoring initializes.
This technique involves spawning a suspended, signed binary ( dpapimig.exe ) and injecting shellcode into its address space, effectively executing the malicious payload before security hooks are fully initialized.
Once launched, the samples check for virtual machines and security tools... The Python source code... rejects lightweight analysis environments
The DLL collected system information and prepared it for Telegram-based transfer
Once launched, the samples check for virtual machines and security tools... The Python source code... rejects lightweight analysis environments
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A blockchain-backed botnet loader that uses Polygon smart contracts for command and control, establishes persistence on Windows, evades analysis, retrieves follow-on payloads, and can support spyware, data theft, and cryptocurrency mining.
A blockchain-backed botnet loader that uses Polygon smart contracts and public RPC endpoints for decentralized C2, establishes persistence, performs reconnaissance, downloads additional payloads, and exfiltrates data including via Telegram API.
Botnet/C2 framework that conceals command-and-control instructions in blockchain (Polygon) smart contracts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.