Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Both screenshots show imported methods assigned to variables, with zlib.decompress prepared for later to handle compressed payloads. It also uses base64.b85decode... One reverses Base85 encoding, and the other converts integers to strings... A large, high-entropy blob serves as the encoded payload. This blob is fed to WgGsgQuaeeYg7e() , which decodes and decrypts it using helper functions.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an example of a full command-and-control implant built with Python.
A Python-based command-and-control and post-exploitation framework that runs code in memory via python.exe, delivers encrypted payloads using ChaCha20 or XOR, and includes modules for credential dumping and post-exploitation activity.
Referenced as the previously used C2 framework before the actors switched to Sliver in the latest Nitrogen campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.