Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They were also observed using a malware researchers named “Tattletale” — a novel tool used to “impersonate users who have signed into the system and gather information related to password policies, security settings, cached passwords, browser information, and storage data.”
They were also observed using a malware researchers named “Tattletale” — a novel tool used to “impersonate users who have signed into the system and gather information related to password policies, security settings, cached passwords, browser information, and storage data.”
They were also observed using a malware researchers named “Tattletale” — a novel tool used to “impersonate users who have signed into the system and gather information related to password policies, security settings, cached passwords, browser information, and storage data.”
They were also observed using a malware researchers named “Tattletale” — a novel tool used to “impersonate users who have signed into the system and gather information related to password policies, security settings, cached passwords, browser information, and storage data.”
They were also observed using a malware researchers named “Tattletale” — a novel tool used to “impersonate users who have signed into the system and gather information related to password policies, security settings, cached passwords, browser information, and storage data.”
They were also observed using a malware researchers named “Tattletale” — a novel tool used to “impersonate users who have signed into the system and gather information related to password policies, security settings, cached passwords, browser information, and storage data.”
9 distinct techniques documented for this family, organized by ATT&CK tactic.
TattleTale also collects the domain controller name and steals the LSA (Local Security Authority) Query Information Policy, which is known to contain sensitive information related to password policies, security settings, and sometimes cached passwords.
we observed two different keylogger tools being deployed... one of which is a previously unreported malware we’ve named TattleTale... The keyloggers were deployed to specific target administrative user accounts and other accounts of interest.
the actors were conducting targeted espionage activity in which they were capturing sensitive documents, keys for cloud infrastructure... other critical authentication keys and certificates... TattleTale’s keylogger capabilities include collecting storage and Edge and Chrome browser data
the actors were conducting targeted espionage activity in which they were capturing sensitive documents, keys for cloud infrastructure... and configuration data for much of the agency’s IT and network infrastructure.
we observed two different keylogger tools being deployed... one of which is a previously unreported malware we’ve named TattleTale... The keyloggers were deployed to specific target administrative user accounts and other accounts of interest.
the actors were conducting targeted espionage activity in which they were capturing sensitive documents, keys for cloud infrastructure (including disaster recovery and backup), other critical authentication keys and certificates, and configuration data
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented keylogger used in the Operation Crimson Palace intrusion set. It fingerprints compromised systems, checks mounted physical and network drives by impersonating a logged-on user, collects the domain controller name, steals LSA Query Information Policy data, and harvests browser/storage data from Edge and Chrome, saving collected data into a .pvk file.
A previously undocumented keylogger used in the Operation Crimson Palace intrusion set. It can fingerprint the compromised system, enumerate mounted physical and network drives by impersonating a logged-on user, collect the domain controller name, steal LSA Query Information Policy data, and harvest browser/storage data from Edge and Chrome, saving collected data into a .pvk file.
A newly observed tool used to impersonate already-signed-in users and collect host/security and credential-related data, including password policy details, security settings, cached passwords, browser information, and storage data—supporting espionage-focused collection and follow-on access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.