Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Campaigns frequently rely on multi-stage, fileless execution chains involving PowerShell and HTA scripts.
...удалось найти два скрытых объекта: код руткита PurpleFox, внедренный в легитимные процессы svchost.exe... PurpleFox... устанавливают драйвер режима ядра...
The HTA decodes the next payload from an array of character codes and launches it... The downloaded PowerShell script is heavily obfuscated... We observed obfuscation techniques unique to each campaign, aiming to mask keywords that trigger alerts in EDRs and SIEMs.
The victim executes a Setup.exe file, which is in fact a legitimate Python interpreter... The same directory also contains a renamed MSHTA executable, iso2022.exe.
The vast majority of detections for mshta.exe come from instances where the command line contains domains that appear to be legitimate services but are hosted on the .cc TLD... Starting in late February 2026... shifted to .vg and .gl TLDs.
Эти компоненты внедряют вредоносные DLL-библиотеки Eternalblue2.dll и Doublepulsar2.dll в процессы lsass.exe и explorer.exe...
The tool is MSHTA, short for Microsoft HTML Application Host, a built-in Windows utility that can run scripts from local files and remote internet locations... Attackers have been using it to deliver some of today’s most harmful malware... All use MSHTA as a stepping stone during early or middle stages of infection.
One of its long-standing delivery methods... remained consistent: launching msiexec from an MSHTA command line in order to download and execute an MSI package disguised as a .png file.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Руткит/загрузчик, внедряющийся в svchost.exe, оставляющий специально подготовленные DLL и устанавливающий драйвер режима ядра для скрытного закрепления и загрузки дополнительных полезных нагрузок.
A rootkit/loader that injects code into svchost.exe, drops crafted DLLs, installs a kernel-mode driver for stealthy persistent execution, and can pull additional payloads such as XMRig.
A malware family observed in MSHTA-related campaigns; the article includes infrastructure IoCs but does not further describe its behavior in this report.
Advanced persistent malware family delivered via MSHTA and msiexec chains. Once installed, it functions as a rootkit-enabled backdoor focused on stealth, persistence, and executing on-demand commands from C2, supporting information theft, surveillance, and DDoS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.