Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Further investigation found that the command installs... NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150... DenoRAT ultimately functioned as a loader for NightshadeC2...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
...a pair of CastleRAT trojan variants enabling system data exfiltration, command execution, and further payload deployment...
C2: 216.126.237[.]122:443 Confirmed via JA3 TLS fingerprinting and malware config extraction
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: Web T1071.001 HTTPS C2 on port 443
used CastleRAT to proxy the replica’s live browser session, attempting logins against financial-institution websites directly from the compromised workstation
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated RAT and information stealer delivered as the final payload in memory. It is decrypted from an encrypted container by a Python-based loader and reflectively mapped into the Python process for execution.
Remote access and command-and-control framework used post-compromise to establish persistent remote access after BumbleBee infection.
A botnet reportedly using 'UAC Prompt Bombing' to bypass Windows Defender.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.