Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“By default, there is one and only one attribute that is written from an Entra user to an Active Directory user and that is the searchableDeviceKey -> msDS-KeyCredentialLink attribute flow… an abuse primitive known as ‘Shadow Credentials’… if we can add a public key to the msDS-KeyCredentialLink attribute of a user, we can obtain a TGT for that user with the private key.”
The choice to use the system's openssl binary rather than a Python cryptography library... The final bundle... is exfiltrated via a raw HTTP POST to the C2's root endpoint, using curl.
“By default, there is one and only one attribute that is written from an Entra user to an Active Directory user and that is the searchableDeviceKey -> msDS-KeyCredentialLink attribute flow… an abuse primitive known as ‘Shadow Credentials’… if we can add a public key to the msDS-KeyCredentialLink attribute of a user, we can obtain a TGT for that user with the private key.”
“By default, there is one and only one attribute that is written from an Entra user to an Active Directory user and that is the searchableDeviceKey -> msDS-KeyCredentialLink attribute flow… an abuse primitive known as ‘Shadow Credentials’… if we can add a public key to the msDS-KeyCredentialLink attribute of a user, we can obtain a TGT for that user with the private key.”
It connects to the device, changes the PSK to all zero if needed, sets up a TLS connection... To work around this, I simply open my own socket and proxy the TLS communication through it.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this malware family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.