Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
It has several means of executing remote tasks, including remote desktop protocol (RDP) and Virtual Network Computing (VNC), despite the malware having shell and PowerShell execution capabilities.
Threat actors are impersonating the group Amnesty International and promising to protect against the Pegasus spyware as part of a scheme to deliver malware. Adversaries have set up a phony website that looks like Amnesty International's.
The ‘rdp’ command is a bit different; the code execution looks like it serves to tell the bot to perform a series of tasks: ... List groups and users
The malware also uses CreateToolhelp32Snapshot to enumerate running processes and then checks if the security analysis tools mentioned below are currently running in the system.
During the first communication, the malware exfiltrates some information about the victim, including the operating system version, whether anti-virus software is installed and the system architecture.
Sarwent contains the usual abilities of a remote access tool (RAT) — mainly serving as a backdoor on the victim machine — and can also activate the remote desktop protocol on the victim machine, potentially allowing the adversary to access the desktop directly.
Sarwent contains the usual abilities of a remote access tool (RAT) ... and can also activate the remote desktop protocol on the victim machine... After that, the adversary can issue commands via the command line or PowerShell or access the desktop remotely via VNC or RDP.
After that, the malware will perform the regular beacon activity to the command and control (C2) site, which is hosted on the same domain.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sarwent is described as a malware family functioning primarily as a downloader rather than a loader in this sample. It establishes persistence via a Run registry key, performs anti-analysis checks for virtualization, sandboxing, debuggers, and security tools, fingerprints the host, communicates with a hard-coded HTTP C2, and can download, execute, update, or delete payloads.
A little-known remote access trojan/backdoor delivered via a fake Amnesty International anti-Pegasus tool. It beacons to C2 infrastructure, exfiltrates host information, supports command execution via shell and PowerShell, enables remote desktop access through RDP and VNC, can upload and execute additional malicious tools, and can exfiltrate arbitrary data.
Sarwent is a malware family that historically functioned as a loader, but newer versions add backdoor/RAT capabilities including executing cmd and PowerShell commands, returning results to C2, and preparing infected systems for later RDP access by adding users, enumerating groups/users, and opening firewall access on the RDP port.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.