Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
creates persistence and injects code into a signed Windows binary before security monitoring initializes.
The Python source code points to a targeted operation. It impersonates a DBeaver installer
creates persistence and injects code into a signed Windows binary before security monitoring initializes.
This technique involves spawning a suspended, signed binary ( dpapimig.exe ) and injecting shellcode into its address space, effectively executing the malicious payload before security hooks are fully initialized.
Once launched, the samples check for virtual machines and security tools... The Python source code... rejects lightweight analysis environments
The DLL collected system information and prepared it for Telegram-based transfer
Once launched, the samples check for virtual machines and security tools... The Python source code... rejects lightweight analysis environments
“some operators are redesigning botnet infrastructure… from traditional command-and-control infrastructure hosted on the public Internet to decentralized, blockchain-based alternatives.”
“Instead of connecting to a dedicated C2 server, infected devices monitor smart contracts deployed on the Polygon and Ethereum blockchains… [which] contain encrypted instructions or pointers to additional infrastructure.”
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A blockchain-based botnet that uses Polygon smart contracts for encrypted commands or pointers to further command-and-control infrastructure, avoiding reliance on a centralized C2 server.
Decentralized botnet that uses Polygon blockchain smart contracts as a command-and-control mechanism, enabling encrypted instructions or pointers to further infrastructure without relying on a dedicated C2 server.
A blockchain-backed botnet loader that uses Polygon smart contracts for command and control, establishes persistence on Windows, evades analysis, retrieves follow-on payloads, and can support spyware, data theft, and cryptocurrency mining.
A blockchain-backed botnet loader that uses Polygon smart contracts and public RPC endpoints for decentralized C2, establishes persistence, performs reconnaissance, downloads additional payloads, and exfiltrates data including via Telegram API.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.