Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5221 was also observed leveraging the PySoxy tunneler and BusyBox to enable post-exploitation activity.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker then created a scheduled task for repeated execution... Telemetry showed the task launching a staged script from C:\ProgramData roughly every 40 minutes, using arguments commonly associated with defense evasion and low-visibility execution.
The intrusion chain began with an obfuscated PowerShell command launched from explorer.exe... The stager contacted attacker infrastructure, downloaded the next stage, and executed it in memory without writing the payload to disk.
The pysoxy YARA rule describes a "SOCKS5 proxy tool used to relay connections," and the ASPX web shell can "act as a Tunnel, using code borrowed from reGeorg."
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source Python-based SOCKS5 proxy tool used by attackers to establish a second, independent access channel into a compromised host, providing more durable access even if the initial PowerShell command-and-control path is blocked.
An open-source Python SOCKS5 proxy used by attackers to route encrypted traffic through a compromised host, creating a secondary encrypted access path and redundant command-and-control capability.
A Python SOCKS5 proxy utility used to relay network connections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.