Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
У разі відкриття архіву та запуску EXE-файлу, комп'ютер буде уражено шкідливою програмою, яку, за сукупністю ознак (незважачи на деякі відмінності), класифіковано як MarsStealer. MarsStelaer - шкідлива програма-стілер, розроблена з використанням мов програмування C/ASM.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
CERT-UA received information about mass distribution of emails with the subject "Нова програма для запису в журналi." The email text impersonates the Ministry of Education and Science of Ukraine and contains a link to a "program" plus an archive password.
...отримання несанкціонованого доступу до комп'ютерів бухгалтерів... наведено декілька прикладів ланцюгів інфікування... (LNK-файлу)... (RAR-архіву з паролем та VBS/BAT файлів) ... Документи.zip / Документи (СУД).rar / Платіжні документи.zip / ... .vbs / ... .bat / Документи.pdf.lnk
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.