Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords.
1 distinct technique documented for this family, organized by ATT&CK tactic.
"Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles." / "Mimikatz ... acquire information about credentials ... including from the credential vault and DPAPI." / "Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Password-decryption tool explicitly described as used by APT39 to recover FTP passwords.
A password recovery tool explicitly described as being used by APT39 to decrypt FTP passwords.
Tool used to decrypt/recover stored FTP passwords for SmartFTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.