Alien
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims. | The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android.
The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android. | A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims.
A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims. | The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android.
We assess that QUAILEGGS likely exploits the aforementioned zero-day vulnerability CVE-2021-1048. Based on Google’s root cause analysis, this vulnerability allows code injection into privileged processes... According to the Linux kernel development git logs, the vulnerability was public since August 2020 and patched in September. However, some Google Pixel phones remained vulnerable until March 2021 and Samsung devices until at least October 2021. | A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims.
The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android. | A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims.
Techniques & procedures
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
The first two — exploitation and privilege escalation — are often grouped in exploit chains, which start by exploiting a remote vulnerability to obtain remote code execution (RCE) privileges... The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN.
Execution
2 techniques
Execution
Privilege Escalation
3 techniques
Privilege Escalation
For example, the implant can inject code that was read earlier from “/system/fonts/NotoColorEmoji.ttf” into the system_server process memory for execution... The overall injection process is achieved using ptrace() and mmap() to inject the code into the target process.
For privilege escalation, the spyware is configured to use a method called QUAILEGGS, or, if QUAILEGGS is not present, it will use a different method called “kmem.” ... We assess that QUAILEGGS likely exploits the aforementioned zero-day vulnerability CVE-2021-1048.
Stealth
4 techniques
Stealth
For example, the implant can inject code that was read earlier from “/system/fonts/NotoColorEmoji.ttf” into the system_server process memory for execution... The overall injection process is achieved using ptrace() and mmap() to inject the code into the target process.
The DEX file thus uses these hooks for two key purposes: Hiding Applications/packages : The plugin in the DEX can hook and filter out a specific package/application name from the list of installed packages and applications.
Credential Access
1 technique
Credential Access
Discovery
2 techniques
Discovery
Collection
2 techniques
Collection
The implant gathers configuration information, but it will also collect contacts, calls and messaging information by copying the content of the files listed below... The content obtained is then written to “/data/local/tmp/wd/”, before being exfiltrated.
This spyware can record audio from different sources by several means. It can record from microphone, earpiece- and VOIP-based calls, using deep-level techniques like memcpy hooking inside audio-related processes, or more simply, creating a RECORD interface using the OpenSLES native library.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-platform webshell management tool that the author notes is technically also a remote access tool, and is being rewritten due to prior design issues.
A Windows infostealer delivered through InstallFix/ClickFix infection chains, where a malicious HTA launches an obfuscated .NET loader in memory.
Primary worker component of the Intellexa/Cytrox spyware suite. It is injected into privileged Android processes, downloads and launches PREDATOR, hooks binder/ioctl and audio-related APIs, sets up inter-process communication and privilege-dependent operations, executes commands from PREDATOR, steals device data, hides apps, and enables surveillance functions such as audio capture.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.