Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE Defense Evasion: T1027 – Obfuscated Files or Information
However, this loader uses a distinct asynchronous procedure call (APC) based process injection technique to inject additional shellcode into the legitimate Microsoft-signed executable Dllhost.exe.
Stage-3... sets up the required syscall stubs... specifically to perform APC-based process injection and inject next stage shellcode into the legitimate, Microsoft-signed Dllhost.exe.
If all of these checks pass, the loader decrypts the next-stage shellcode in memory and executes it... The loader uses the ChaCha20 algorithm with a hardcoded key and nonce for decryption.
Direct-Sys Loader, which performs three separate anti-sandbox and anti-analysis checks before decrypting and executing the next-stage shellcode.
The loader queries display device information via EnumDisplayDevicesA... decrypts a hardcoded list of known hypervisor and analysis-environment display device strings... If any match is detected, the loader silently terminates execution.
Before decrypting and executing the next in-memory shellcode, the Stage-1 loader performs three primary checks... Text File Check... Active Process Check... Display Device Check.
It then proceeds to enumerate all active processes on the system, collecting the Process ID, Session ID, Process Name, and corresponding command-line arguments.
Direct-Sys Loader, which performs three separate anti-sandbox and anti-analysis checks before decrypting and executing the next-stage shellcode.
The loader queries display device information via EnumDisplayDevicesA... decrypts a hardcoded list of known hypervisor and analysis-environment display device strings... If any match is detected, the loader silently terminates execution.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An intermediate loader used in related OnionDrop delivery chains, particularly in the Vidar path, adding an extra stage before the final stealer payload runs.
A novel malware loader delivered via malicious ZIP archives hosted on GitHub user attachments. It is sideloaded through a legitimate Microsoft-signed executable, performs multiple anti-sandbox and anti-analysis checks, decrypts and executes next-stage shellcode using direct syscalls, and loads additional stages in memory to ultimately deploy CGrabber Stealer.
A previously unreported loader that uses ChaCha20 in-memory decryption, direct syscall stubs, and layered anti-analysis checks before decrypting and executing later-stage payloads, including shellcode and APC-based injection stages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.