Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
A DLL masquerading as a Windows component loads via the Task Scheduler, decrypts its configuration from the registry, and injects position-independent shellcode into svchost.exe.
The DLL stores its encrypted configuration in the Windows registry under a path that itself is encrypted. A heartbeat timestamp (FILETIME) at bytes 0-7 of the registry value is updated after each successful beacon... | ... it wipes the encrypted registry blob via RegDeleteValue ...
The DLL, the VM, and the beacon each carry their own encryption, their own API resolution, and their own C2 channel ... Every string, API name, DLL name, and code chunk in the blob is encoded with a cascading XOR cipher.
The beacon disguises its check-in as a request for a PNG image ... The server's response contains actual PNG data, but with a custom chunk type.
The payload is assembled from bytecode at runtime ... resolving APIs through hash lookups ... The VM resolves all APIs by walking the Process Environment Block (PEB), iterating loaded modules, and comparing DJB2 hashes of export names.
The entry point is a 200KB DLL named WptsExtensions.dll, the exact name of a legitimate Windows Task Scheduler extension library. It exports the same five functions ... and spoofs its version info as "Microsoft Corporation, v10.0.19041.1023".
After loading its configuration, the DLL injects the VM shellcode into a svchost.exe service host process.
If the difference exceeds a configurable threshold ... the DLL enters its self-destruct sequence: it wipes the encrypted registry blob via RegDeleteValue, then schedules its own DLL file for deletion on the next reboot using MoveFileExW ...
... schedules its own DLL file for deletion on the next reboot using MoveFileExW with the MOVEFILE_DELAY_UNTIL_REBOOT flag.
The DLL stores its encrypted configuration in the Windows registry under a path that itself is encrypted. A heartbeat timestamp (FILETIME) at bytes 0-7 of the registry value is updated after each successful beacon... | ... it wipes the encrypted registry blob via RegDeleteValue ...
The process enumeration has a fallback chain. It first tries the Toolhelp API ... If that fails, it falls back to NtQuerySystemInformation with information class 5 (SystemProcessInformation) ... Each process name is hashed with MD5.
The beacon profiles the machine, phones home over HTTPS disguised as PNG image requests ... GET /assets/static/img/I4o8Pp_41.png HTTP/1.1 ... After execution, the results are XXTEA-encrypted and sent back via HTTP POST to a separate .php endpoint.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.