Fiber.Program is a .NET loader observed in at least two multi-stage malware delivery chains. It is described as a Babel-obfuscated .NET Framework 4.5 assembly, in one case masquerading as Microsoft.Win32.TaskScheduler v2.12.2.0, and is delivered reflectively from steganographically concealed payloads embedded in fake JPEG files. In the documented chains, an initial VBScript or obfuscated JavaScript/WSH dropper launches PowerShell via WMI Win32_Process.Create, which downloads a JPEG from either Lighthouse Storage IPFS URLs or magina.online, extracts hidden data between markers such as IN- / -in1, decodes the embedded .NET assembly, and invokes Fiber.Program.Main.
Its capabilities include payload retrieval, persistence, process injection, and anti-analysis. Reported imports and behavior include VirtualAllocEx, WriteProcessMemory, and CreateProcess; scheduled-task persistence via Microsoft.Win32.TaskScheduler.dll; and references to AesCryptoServiceProvider. One observed configuration passed to Fiber.Program.Main included an IPFS URL, drop paths, host process names, a task name, and persistence flags. In the Formbook chain, Fiber.Program created a scheduled task named Task_Name, copied or launched a VBS file from C:\Users\Public\Downloads\Name_File.vbs, downloaded a second IPFS-hosted payload disguised as a JPEG, and injected the final Formbook stealer into wscript.exe. In the XWorm chain, Fiber.Program exposed a 19-parameter Main() entry point, reused public RunPE/process-hollowing code under the namespace HackForums.gigajew.x64, fetched a second steganographic JPEG from magina.online, repaired a deliberately corrupted PE, and process-hollowed the final XWorm RAT (XClient variant) into Caspol.exe.
Anti-analysis features directly reported for the XWorm-associated sample include VM detection, anti-debugging, anti-profiler checks, analysis-tool detection, anti-tamper logic, and encrypted strings. The same sample also contained the unobfuscated Portuguese method name VerificarMinutos. Associated malware families delivered by Fiber.Program include Formbook and XWorm. Reported infrastructure and artifacts include Lighthouse Storage IPFS gateway URLs https://gateway.lighthouse.storage/ipfs/bafybeienmgwcoj64jx2t5nmlik2wba3xsil6bmjzqkszqpwyadgvl64mxe and https://gateway.lighthouse.storage/ipfs/bafybeigl7leimjh6izjxqapmyjzuobigsz6l7y2lvfcyrnyw5nl254m6aq, as well as magina.online URLs https://magina.online/MSI_111454.png and https://magina.online/img_152603.png. Reported hashes for Fiber.Program samples include SHA256 9fe957e5be9729b4fe64906b95a6ff2931d42ff2805ad12069b99e3fdc8b6ae3 and SHA256 53c3e0f8627917e8972a627b9e68adf9c21966428a85cb1c28f47cb21db3c12b. Attribution is not uniform across all observed use: the Formbook case was assessed as inconclusive due to commodity malware usage, while the XWorm campaign showed strong indicators of a Brazilian operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
gesturality. Get ( "Win32_Process" ). Create (proposing, null , perineptunium, drumble);
MITRE ATT&CK Mapping Tactic Technique ID ... Persistence Scheduled Task/Job T1053.005
var proposing = 'powershell.exe -ExecutionPolicy Bypass -NoProfile ' + '-WindowStyle Hidden -Command "IEX $env:INTERNAL_DB_CACHE"';
MITRE ATT&CK Mapping Tactic Technique ID ... Persistence Scheduled Task/Job T1053.005
Load() implements a textbook process hollowing sequence: CreateProcess (CREATE_SUSPENDED) → ZwUnmapViewOfSection(target base) → VirtualAllocEx(target, payload size, RWX) → WriteProcessMemory(target, payload bytes) → SetThreadContext / GetThreadContext → ResumeThread
It uses a three-layer obfuscation scheme: Unicode character separators... A digammate() helper... A gerenda string builder that assembles the real payload one character at a time across thousands of lines
MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Masquerading T1036 Payload disguised as .png on Internet Archive
Loaded via [AppDomain]::CurrentDomain.Load(), it presents itself to tools like ilspy as Microsoft.Win32.TaskScheduler v2.12.2.0
Load() implements a textbook process hollowing sequence: CreateProcess (CREATE_SUSPENDED) → ZwUnmapViewOfSection(target base) → VirtualAllocEx(target, payload size, RWX) → WriteProcessMemory(target, payload bytes) → SetThreadContext / GetThreadContext → ResumeThread
MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Deobfuscate/Decode Files T1140 Multi-layer base64 + XOR decryption at runtime
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: Web Protocols T1071.001
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Babel-obfuscated .NET loader disguised as Microsoft.Win32.TaskScheduler v2.12.2.0. It is configuration-driven with a 19-parameter Main() entry point, fetches payloads from steganographic JPEGs, includes anti-analysis and anti-tamper features, and uses process hollowing code under the HackForums.gigajew.x64 namespace to inject the final payload into Caspol.exe.
A .NET loader hidden inside a JPEG on IPFS. It is reflectively loaded by PowerShell, creates scheduled-task persistence, downloads the final payload from a second IPFS URL, and process-injects the final Formbook payload into wscript.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.