Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Chrome exploit involves chaining two vulnerabilities that have already been patched, with one assigned as CVE-2019-5782, while the other does not have an associated CVE identifier. The attacker reused the POC code to implement a weaponized version of it. | Besides the SLUB variant, we found two other malware we named dneSpy and agfSpy... While examining dneSpy, we found that the sample C&C server is configured to target certain types of victims, with location as a criteria.
We also found another exploit abusing CVE-2020-0674, an Internet Explorer vulnerability injected into compromised websites. In particular, it runs a PowerShell loader that will infect victims with three different binaries. | Besides the SLUB variant, we found two other malware we named dneSpy and agfSpy... While examining dneSpy, we found that the sample C&C server is configured to target certain types of victims, with location as a criteria.
If instructed in the LPE (Local Privilege Escalation) column, the PowerShell loader may instruct downloading and executing an LPE binary exploiting CVE-2019-1458. This binary may download and execute the backdoors with system privileges.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Besides the SLUB variant, we found two other malware we named dneSpy and agfSpy... While examining dneSpy, we found that the sample C&C server is configured to target certain types of victims, with location as a criteria.
"Also, dneSpy and agfSpy are based on custom and newly developed code."
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution, the shellcode first de-obfuscates “ws2_32.dll” and “_.dll,” and then resolves the API modules based on their hashes using a known technique.
The new SLUB variant interacts with the Mattermost server to keep track of the deployment across multiple infected machines.
the C&C communication happens to be with TCP at DNS standard port (53) to avoid being blocked by a firewall.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom espionage backdoor referenced as part of Operation Earth Kitsune tooling; described as newly developed code with limited code-sharing indicators across older APT37-attributed samples.
A spying/backdoor malware delivered alongside SLUB in the campaign. It exfiltrates information, can control infected systems, targets certain victims based on location criteria, and registers infected hosts on its C2 to avoid reinfection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.