Da Vinci
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
THE GALILEO SOLUTION IS MUCH BETTER THAN THE DA VINCI THEY HAVE IN TOLUCA.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Credential Access
1 techniqueCollection
4 techniquesCovert collection of emails, text message, phone call history and address books; Keystroke logging
Record audio from phone calls; Capture audio and video stream from device memory to bypass cryptography of Skype sessions; Use microphones on device to collect ambient background noise and conversations
Exfiltration
1 techniqueRCS is a management platform that allows operators to remotely deploy exploits and payloads against targeted systems, remotely manage devices once compromised, and exfiltrate data for remote analysis.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier Hacking Team surveillance/intrusion platform referenced as an existing deployment in Toluca that the customer considered unsatisfactory.
Hacking Team RCS platform variant used for remote monitoring and data exfiltration from compromised devices.
Commercial surveillance spyware platform sold by Hacking Team that enables monitoring of cell phone conversations, emails, Skype calls, and spying through a target’s webcam and microphone.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.