Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims. | The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android.
The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android. | A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims.
A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims. | The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android.
We assess that QUAILEGGS likely exploits the aforementioned zero-day vulnerability CVE-2021-1048. Based on Google’s root cause analysis, this vulnerability allows code injection into privileged processes... According to the Linux kernel development git logs, the vulnerability was public since August 2020 and patched in September. However, some Google Pixel phones remained vulnerable until March 2021 and Samsung devices until at least October 2021. | A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims.
The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android. | A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Predator от Cytrox / Intellexa работает двухкомпонентно: Alien ломает устройство, Predator устанавливает модули слежки.
Predator от Cytrox / Intellexa работает двухкомпонентно: Alien ломает устройство, Predator устанавливает модули слежки.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Webshells are often used during data breaches. For example, an attacker can find the password of MySQL in phpMyAdmin/config.inc.php
Web applications remain one of the most common attack surfaces... arbitrary code execution obtained through a web application often serves as the initial foothold. | If we discover a SQL injection vulnerability, we can exploit it using sqlmap... sqlmap.py -u 'YOUR URL' --os-shell
For example, the implant can inject code that was read earlier from “/system/fonts/NotoColorEmoji.ttf” into the system_server process memory for execution... The overall injection process is achieved using ptrace() and mmap() to inject the code into the target process.
For privilege escalation, the spyware is configured to use a method called QUAILEGGS, or, if QUAILEGGS is not present, it will use a different method called “kmem.” ... We assess that QUAILEGGS likely exploits the aforementioned zero-day vulnerability CVE-2021-1048.
If you are concerned about WAFs and IDSs, you can enable Event Horizon for evasion.
For example, the implant can inject code that was read earlier from “/system/fonts/NotoColorEmoji.ttf” into the system_server process memory for execution... The overall injection process is achieved using ptrace() and mmap() to inject the code into the target process.
Webshells are often used during data breaches. For example, an attacker can find the password of MySQL in phpMyAdmin/config.inc.php
The DEX file thus uses these hooks for two key purposes: Hiding Applications/packages : The plugin in the DEX can hook and filter out a specific package/application name from the list of installed packages and applications.
The core idea is to obtain all running processes from the remote server and compare them against a database of known anti-virus software.
exec ( 'tasklist /NH /FO CSV' , $outputLines ); ... The core idea is to obtain all running processes from the remote server and compare them against a database of known anti-virus software.
The implant gathers configuration information, but it will also collect contacts, calls and messaging information by copying the content of the files listed below... The content obtained is then written to “/data/local/tmp/wd/”, before being exfiltrated.
This spyware can record audio from different sources by several means. It can record from microphone, earpiece- and VOIP-based calls, using deep-level techniques like memcpy hooking inside audio-related processes, or more simply, creating a RECORD interface using the OpenSLES native library.
Using Alien’s built-in SOCKS5 proxy, external tools such as sqlmap can access internal web applications through the compromised server.
Using Alien’s built-in SOCKS5 proxy, external tools such as sqlmap can access internal web applications through the compromised server.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alien is presented as an offensive security/webshell framework with a plugin architecture that loads and executes payloads across multiple server-side environments, including PHP, ASP, ASPX, and JSP/NebulaPulsar/DarkMatter.
Alien is presented as a webshell/backdoor framework used for post-exploitation. It forwards payloads to the Event Horizon obfuscation framework, which transforms HTTP requests and responses and can generate compatible OneShell payloads with de-obfuscation routines.
A webshell management tool/framework discussed by the author as a client-side tool for interacting with lightweight server-side webshells ("OneShells") and supporting post-exploitation functionality.
An offensive framework/project under which NebulaPulsar is developed as a sub-project for experimenting with multi-platform webshell and implant techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.