Sefirah
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once the environment was prepped, a binary called “sefirah” dropped onto the machine. It’s written in Rust... The payload ran eight data collectors in parallel: Crypto wallets... Discord tokens... Developer credentials... Browser data... Screenshots... File search... Everything was bundled into a JSON package and sent to a command-and-control server
Once the environment was prepped, a binary called “sefirah” dropped onto the machine. It’s written in Rust... The payload ran eight data collectors in parallel: Crypto wallets... Discord tokens... Developer credentials... Browser data... Screenshots... File search... Everything was bundled into a JSON package and sent to a command-and-control server
Techniques & procedures
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
A fake repository impersonating OpenAI’s Privacy Filter tool climbed to the top of Hugging Face’s trending list last week... Attackers cloned its documentation almost word-for-word, creating a mirror repository that looked credible enough to fool experienced developers at first glance.
Execution
5 techniques
Execution
followed by the creation of a scheduled task dressed up as a Microsoft Edge update to lock in SYSTEM-level persistence.
The repository had typosquatted OpenAI's legitimate Privacy Filter release, copied its model card nearly verbatim, and shipped a loader.py file that fetches and executes infostealer malware on Windows machines.
The command, which is executed in an invisible window, downloads a batch file (start.bat) that performs privilege escalation, downloads the final payload (sefirah), adds it to Microsoft Defender's exclusions for it, and executes it.
Persistence
1 technique
Persistence
Privilege Escalation
2 techniques
Privilege Escalation
Stealth
2 techniques
Stealth
Credential Access
4 techniques
Credential Access
Browser data: Saved passwords, credit cards, cookies, and autofill data from Chrome, Edge, Firefox, Brave, and any other Chromium or Gecko-based browser on the machine.
Developer credentials: SSH keys, FTP credentials (with specific attention to FileZilla), and VPN configs.
Discovery
2 techniques
Discovery
Collection
3 techniques
Collection
Command and Control
2 techniques
Command and Control
Exfiltration
1 technique
Exfiltration
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based information stealer delivered via a fake Hugging Face repository impersonating OpenAI’s Privacy Filter. It establishes persistence, evades defenses by disabling AMSI/ETW and adding Defender exclusions, then steals wallet data, Discord tokens, developer credentials, browser secrets, screenshots, and sensitive files before exfiltrating them to C2.
A Rust-based infostealer delivered via a malicious Hugging Face repository. It steals browser data, Discord tokens, cryptocurrency wallets, SSH/FTP/VPN credentials, sensitive local files, system information, and multi-monitor screenshots, then compresses and exfiltrates the data to a C2 server. It also includes anti-analysis checks for virtual machines, sandboxes, debuggers, and analysis tools.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.