Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker then created a scheduled task for repeated execution... Telemetry showed the task launching a staged script from C:\ProgramData roughly every 40 minutes, using arguments commonly associated with defense evasion and low-visibility execution.
The intrusion chain began with an obfuscated PowerShell command launched from explorer.exe... The stager contacted attacker infrastructure, downloaded the next stage, and executed it in memory without writing the payload to disk.
PySoxy gave the attacker a second, independent route back into the host. This second channel used different infrastructure and a different traffic pattern than the first.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source Python-based SOCKS5 proxy tool used by attackers to establish a second, independent access channel into a compromised host, providing more durable access even if the initial PowerShell command-and-control path is blocked.
An open-source Python SOCKS5 proxy used by attackers to route encrypted traffic through a compromised host, creating a secondary encrypted access path and redundant command-and-control capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.