Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Noticing that aspects of the above were being detected by ESET as FrostyNeighbor, we went hunting on their other detections to try to find other samples.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
var taskName = "QQ Automated Workflows"; ... a0_0x2838df.Arguments = a0_0x16e3db; a0_0x225f2e.Settings.MultipleInstances = 1;
Execution T1204.002 User Execution: Malicious File T1053.005 Scheduled Task/Job: Scheduled Task
Execution T1204.002 User Execution: Malicious File T1053.005 Scheduled Task/Job: Scheduled Task T1059 Command and Scripting Interpreter
The attacker had already achieved macro execution to run... when the captcha is correct, the string uOMeDrJtHN is being passed to unprotect the document, and the function llolo10ooll executed.
var a0_0x16e3db = "//B //E:jscript " + String.fromCharCode(34) + programPath + ":Zone.Identifier" + String.fromCharCode(34) + " /QQEX";
Files that leverage anti-analysis techniques can often be interesting threads to pull on... The macro in the document was constructed in the below, self-documented, code block... The rest of the obfuscation leverages 1, L, 0 and o.
T1036.005 Masquerading: Match Legitimate Resource Name or Location
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.