Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WailingCrab, also known as WikiLoader, is a malware loader distributed through emails using delivery- and transportation-themed lures and attributed to Bamboo Spider.
IBM X-Force researchers have been tracking developments to the WailingCrab malware family... WailingCrab, also known as WikiLoader, is a sophisticated, multi-component malware... Since mid-2023, WailingCrab’s backdoor component has communicated with the C2 using the MQTT protocol.
IBM X-Force researchers have been tracking developments to the WailingCrab malware family... WailingCrab, also known as WikiLoader, is a sophisticated, multi-component malware... Since mid-2023, WailingCrab’s backdoor component has communicated with the C2 using the MQTT protocol.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
WailingCrab was first observed in December 2022, and since then it has been used extensively in email campaigns to deliver the Gozi backdoor often against Italian targets. In recent months, Hive0133 has targeted organizations beyond Italy with email campaigns delivering WailingCrab, frequently using themes such as overdue delivery or shipping invoices.
Additionally, WailingCrab makes use of code obfuscation, anti-analysis, and anti-sandbox techniques throughout its code.
IBM X-Force researchers have been tracking developments to the WailingCrab malware family, in particular, those relating to its C2 communication mechanisms, which include misusing the Internet-of-Things (IoT) messaging protocol MQTT.
Since mid-2023, WailingCrab’s backdoor component has communicated with the C2 using the MQTT protocol which is a lightweight IoT messaging protocol. In this instance, WailingCrab uses the legitimate, third-party broker, broker.emqx[.]io, which allows it to hide the true address of the C2 server.
successful requests to C2-controlled servers are often necessary to retrieve the next stage... C2 -> broker.emqx.io (Client Topic) -> Backdoor ... Message: Either ‘0’ or payload message ... download path ... C2 -> broker.emqx.io (Client Topic 3) -> Backdoor ... Message: Base64 encoded shellcode payload
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercrime tool mentioned solely as a prior malware example using MQTT communications.
A malware loader delivered through delivery- and transportation-themed phishing emails.
Mentioned only as a comparison for its earlier use of an MQTT-based command channel.
Multi-component malware distributed through phishing emails whose backdoor component uses MQTT for command-and-control, leveraging a legitimate third-party broker to conceal the true C2 server and blend with legitimate IoT traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.