Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
However, this loader uses a distinct asynchronous procedure call (APC) based process injection technique to inject additional shellcode into the legitimate Microsoft-signed executable Dllhost.exe.
If all of these checks pass, the loader decrypts the next-stage shellcode in memory and executes it... The loader uses the ChaCha20 algorithm with a hardcoded key and nonce for decryption.
Direct-Sys Loader, which performs three separate anti-sandbox and anti-analysis checks before decrypting and executing the next-stage shellcode.
The same three anti-analysis checks are performed for a third time, along with a check for whether the machine is running in a Commonwealth of Independent States (CIS) locale and a check for a mutex indicating the stealer is already running.
Direct-Sys Loader, which performs three separate anti-sandbox and anti-analysis checks before decrypting and executing the next-stage shellcode.
If all checks pass, the stealer establishes a connection with a remote command-and-control (C2) server... The data is aggregated in a ZIP archive and sent via a POST request to the C2 endpoint /api/upload/complete or sent in 1MB chunks to the /api/upload/chunk endpoint.
Organizations can defend against this malware by monitoring for syscall stubs in memory, suspicious DLL sideloading activity, outbound POST requests to the attacker’s C2 endpoints and in-memory patching of Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) APIs, another evasive measure leveraged in this campaign.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.