Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A vulnerability in the web filtering features of multiple Cisco products could allow an unauthenticated, remote attacker to bypass web reputation filters and threat detection mechanisms on an affected device and exfiltrate data from a compromised host to a blocked external server. This vulnerability is due to inadequate inspection of the Server Name Identification (SNI) header in the SSL/TLS handshake.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
we realised that we could exfiltrate data utilising extensions of the Client Hello of the TLS protocol. We chose the SNI field as an exfiltration container because it was the one extension that was never manipulated or changed by any of the in-line security solutions.
The following analytic identifies the use of SNICat tool commands within the TLS SNI field, indicating potential data exfiltration attempts... SNICat is a known tool for covert data exfiltration using TLS.
FortiOS may allow a privileged attacker to disclose sensitive information via SNI Client Hello TLS packets.
This blog post describes how we discovered a new stealthy method of data exfiltration that specifically bypasses network security solutions such as web proxies, next generation firewalls (NGFW), and dedicated solutions for TLS interception and inspection.
By using our exfiltration method SNIcat , we found that we can bypass a security solution performing TLS inspection, even when the Command & Control (C2) domain we use is blocked by common reputation and threat prevention features built into the security solutions themselves.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used for covert data exfiltration over TLS by embedding commands in the TLS SNI/server_name field.
A tool used to exfiltrate sensitive information via SNI Client Hello TLS packets to bypass FortiGate security profiles.
A stealthy data exfiltration technique/tool that abuses the TLS Client Hello Server Name Indication (SNI) field to bypass TLS inspection, web proxies, NGFWs, and other network security controls, enabling outbound data transfer and C2 communication to blocked domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.