Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
When decrypted, the MP4 file is an additional JavaScript snippet that starts PowerShell... it launches PowerShell with an encoded command... Nodersok’s infection continues by launching several instances of PowerShell to download and run additional malicious modules.
KovCoreG’s attacks are socially engineered malvertisments that lure unwitting users into downloading a software package needed to update their supposedly out-of-date Adobe Flash application. However, it instead drops a malicious HTML application (HTA) file named Player{timestamp}.hta . When the victim executes the HTA file...
All of the relevant functionalities reside in scripts and shellcodes that are almost always coming in encrypted, are then decrypted... it hides the malicious PowerShell script in an environment variable named “deadbeef”... All the modules are hosted on the C&C servers in RC4-encrypted form
we uncovered this campaign in mid-July, when suspicious patterns in the anomalous usage of MSHTA.exe emerged... Like the Astaroth campaign, every step of the infection chain only runs legitimate LOLBins, either from the machine itself ( mshta.exe , powershell.exe )
Immediately after its execution, it performs the following anti-debugging and anti-analysis checks: Searching for blacklisted processes and modules... Checking if the number of cores is too small Checking if the process is being debugged Checking if the Sleep function is being manipulated
Immediately after its execution, it performs the following anti-debugging and anti-analysis checks: Searching for blacklisted processes and modules... Checking if the number of cores is too small Checking if the process is being debugged Checking if the Sleep function is being manipulated
It has two purposes: Connect back to the remote C&C, and Receive HTTP requests to proxy back to it It supports the SOCKS4A protocol.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware referenced as another notable NodeJS-based threat.
Fileless malware campaign that abuses legitimate tools including mshta.exe, PowerShell, Node.exe, and WinDivert to install an in-memory Node.js-based payload that turns infected Windows machines into zombie proxy nodes and can support SOCKS4A-based proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.