Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
If instructed in the LPE (Local Privilege Escalation) column, the PowerShell loader may instruct downloading and executing an LPE binary exploiting CVE-2019-1458. This binary may download and execute the backdoors with system privileges.
We also found another exploit abusing CVE-2020-0674, an Internet Explorer vulnerability injected into compromised websites. In particular, it runs a PowerShell loader that will infect victims with three different binaries. | Besides the SLUB variant, we found two other malware we named dneSpy and agfSpy... Our analysis revealed that the samples did not contain any functionality related to financial interests — instead, we found features intended to exfiltrate information and control infected systems.
The Chrome exploit involves chaining two vulnerabilities that have already been patched, with one assigned as CVE-2019-5782, while the other does not have an associated CVE identifier. The attacker reused the POC code to implement a weaponized version of it. | Besides the SLUB variant, we found two other malware we named dneSpy and agfSpy... Our analysis revealed that the samples did not contain any functionality related to financial interests — instead, we found features intended to exfiltrate information and control infected systems.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Besides the SLUB variant, we found two other malware we named dneSpy and agfSpy... Our analysis revealed that the samples did not contain any functionality related to financial interests — instead, we found features intended to exfiltrate information and control infected systems.
"one of the espionage backdoors, named agfSpy, received a 'JSON' configuration with a list of native Windows commands to execute."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution, the shellcode first de-obfuscates “ws2_32.dll” and “_.dll,” and then resolves the API modules based on their hashes using a known technique.
The new SLUB variant interacts with the Mattermost server to keep track of the deployment across multiple infected machines.
the C&C communication happens to be with TCP at DNS standard port (53) to avoid being blocked by a firewall.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage backdoor used in Operation Earth Kitsune; receives JSON tasking to run native Windows commands and exfiltrates results to its C2, with collection patterns focused on user directories and document extensions (notably .hwp).
A spying/backdoor malware delivered with SLUB during Operation Earth Kitsune. It is described as focused on information exfiltration and control of infected systems rather than financial theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.