Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The watchdog uses GetWindowTextW() and FindWindowW() to identify analyst tool titles and window classes; opcode 80 enumerates visible windows.
The watchdog performs process enumeration via CreateToolhelp32Snapshot() and searches for analysis-tool process names; opcode 65 retrieves running-process information.
Opcode 39 starts a keylogger using a WH_KEYBOARD_LL hook, and opcode 40 flushes captured keystrokes to C2.
The WPF credential-prompt overlay collects phone, PIN, or text values, and the submit action sends captured values to C2.
When a victim opens a monitored banking domain, the agent establishes a WebSocket connection to wss://mxtestacionamentos[.]com/ws; campaign APIs use HTTPS endpoints.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.