FatMalloc is a multi-stage 64-bit MinGW crypter observed in a large-scale malvertising campaign active since at least January 2026. The campaign targeted U.S. users searching Google for tax-related forms such as W-2 and W-9, redirecting them through domains including anukitax[.]com and bringetax[.]com to install a rogue ScreenConnect MSI (for example, form_w9.msi, SHA256 7509365935fc1bfadba20656698d3a29051031635419043bc2bc45116106e026). After initial access via the rogue ScreenConnect installer, attackers deployed FatMalloc from C:\Windows\SystemTemp\ScreenConnect\25.9.5.9473\crypteds.exe, often alongside FleetDeck and multiple ScreenConnect relay instances for redundant persistence and resilience.
FatMalloc uses anti-analysis and staged loading techniques. It allocates and zeroes 2 GB of memory as an anti-sandbox and AV evasion measure, then executes shellcode indirectly via the Windows multimedia timer API timeSetEvent rather than a direct thread or jump. It contains an XOR-encrypted shellcode blob that decodes a loader using a block-based XOR scheme and a CHOC configuration block. The decoded loader dynamically resolves APIs, supports CLR hosting APIs from mscoree.dll, and decompresses the final payload with RtlDecompressBuffer using LZNT1.
The final payload delivered by FatMalloc was HwAudKiller (SHA256 033f42102362a8d8d4bdba870599eb5e0c893d8fd8dd4bc2a4b446cbbeb59b99), a BYOVD tool that drops a kernel driver as Havoc.sys to %TEMP% and creates a kernel service named Havoc. The embedded driver was a legitimate signed Huawei audio driver, HWAuidoOs2Ec.sys (SHA256 5abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33db), weaponized to terminate security products from kernel mode via device \.\HWAudioX64 and IOCTL 0x2248DC. Reported targets included Microsoft Defender, Kaspersky, and SentinelOne. In related intrusions, after defenses were disabled, attackers dumped LSASS and used tools such as NetExec for credential harvesting, behavior assessed as consistent with pre-ransomware activity or initial access brokerage.
The broader campaign used Google Ads, rogue tax-themed sites, cloaking through Adspect and JustCloakIt, and shared 4sync-hosted payload infrastructure. Huntress linked more than 60 rogue ScreenConnect sessions to this activity. An exposed operator directory also contained a fake Chrome update lure and Russian-language JavaScript comments, suggesting a likely Russian-speaking developer, but no specific threat actor attribution for FatMalloc itself was provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Starting at offset 0xF4 the shellcode is XOR-encrypted... The decoded shellcode resolves APIs by building strings character-by-character on the stack to evade static string detection.
The shellcode then decrypts itself using a block-based XOR method before decompressing the final HwAudKiller payload into memory using LZNT1.
FatMalloc allocates 2GB of memory and fills it with zeros... some sandboxes typically run with limited memory, so a 2GB allocation will likely fail and since the payload only executes inside the if (Block) branch, a failed allocation causes the malware to silently exit.
FatMalloc allocates 2GB of memory and fills it with zeros... some sandboxes typically run with limited memory, so a 2GB allocation will likely fail and since the payload only executes inside the if (Block) branch, a failed allocation causes the malware to silently exit.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage crypter used after initial access via ScreenConnect. It allocates 2GB of memory to evade AV emulation, exits in constrained sandboxes, executes shellcode via the Windows multimedia timer API, then decrypts and decompresses the final HwAudKiller payload in memory.
A multi-stage crypter/loader delivered via rogue ScreenConnect that uses anti-analysis techniques including a 2GB memory allocation, indirect shellcode execution via timeSetEvent callbacks, XOR-decrypted shellcode, and CHOC-configured payload unpacking to load the final in-memory payload HwAudKiller.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.