Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ultimately, this Python loader decrypts and runs NightshadeC2 directly in memory. NightshadeC2 acts as a fully featured information stealer.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
...a pair of CastleRAT trojan variants enabling system data exfiltration, command execution, and further payload deployment...
The chain then leveraged a likely AI-generated PowerShell stage to install the Deno runtime and launch the next-stage Deno-based loader, DinDoor.
DenoRAT ultimately functioned as a loader for NightshadeC2, receiving a task from the C2 that launched a Python-based in-memory loader to decrypt and execute the NightshadeC2 RAT/infostealer payload.
The attack begins with a ClickFix-style social engineering lure. Specifically, the attackers trick a victim into executing a command via the Windows Run prompt. | Specifically, the attackers trick a victim into executing a command via the Windows Run prompt. This command downloads and runs a Microsoft Installer (MSI) file.
NightshadeC2 acts as a fully featured information stealer. It decrypts container files using an AES-256 key derived from the hardcoded phrase “MoscauHighSmoke”.
C2: 216.126.237[.]122:443 Confirmed via JA3 TLS fingerprinting and malware config extraction
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: Web T1071.001 HTTPS C2 on port 443
used CastleRAT to proxy the replica’s live browser session, attempting logins against financial-institution websites directly from the compromised workstation
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An in-memory deployed information stealer used in the final stage of the chain to steal credentials and browser data; it is decrypted and executed by a Python-based reflective PE loader.
A sophisticated RAT and information stealer delivered as the final payload in memory. It is decrypted from an encrypted container by a Python-based loader and reflectively mapped into the Python process for execution.
Remote access and command-and-control framework used post-compromise to establish persistent remote access after BumbleBee infection.
A botnet reportedly using 'UAC Prompt Bombing' to bypass Windows Defender.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.