Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
This program provides functionality to decode passed parameters on the fly, using Xor single-byte decode... Both command and script can be further encoded using single-byte XOR (will produce output Base64 encoded) for better OpSec experience.
if compiled with .NET Framework 4.7.1+ an additional functionality is included that allows to unload DLLs constituting CLM bypass artefacts and attempts to delete them afterwards
the code that ran in explorer.exe, outlook.exe, svchost.exe, and taskhostw.exe executed instances of the werfault.exe process and injected the following tools into the instances: SharpView ... Rubeus ... Stracciatella ... Seatbelt ... PowerShellRunner ... SharpChromium
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.