MY24 is a Windows backdoor observed in politically themed intrusion activity using malicious document lures related to India, Kashmir, intelligence, and terrorism. It has been delivered through exploit chains involving the InPage word processor and through malicious Microsoft Word documents, and it has also been linked through infrastructure overlap to later activity associated with ArtraDownloader and the BITTER threat cluster.
The malware operates as a command-and-control backdoor using raw sockets and a custom protocol with XOR-encrypted traffic. It decodes embedded strings through a simple byte transformation and connects to operator-controlled infrastructure to receive commands. Supported functionality includes collection of basic victim information such as Windows version, username, and computer name; drive and file enumeration; file read and write operations; spawning and interacting with a command shell; listing network communications; enumerating processes; and terminating processes. These capabilities make it suitable for reconnaissance and post-compromise interactive control.
MY24 contains evidence of attempted persistence logic through generation of a Startup-folder execution path, although reporting indicates this path was not actually used, suggesting incomplete or unused persistence functionality in the analyzed sample. The malware also exhibited implementation flaws that could leak portions of process stack memory in command responses due to improper buffer handling.
Operationally, MY24 has been associated with document-based delivery in South Asia-focused campaigns and with tradecraft overlapping other malware used in the same ecosystem. Its observed use alongside InPage exploitation and later infrastructure connections to ArtraDownloader indicate it forms part of a broader Windows intrusion toolset used for targeted espionage-oriented operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The decoy documents used by the InPage exploits suggest that the targets are likely to be politically or militarily motivated. They contained subjects such as intelligence reports and political situations related to India, the Kashmir region, or terrorism being used as lure documents.
The shellcode then gets the address of the WinExec function, which in turn is used to execute the following command:
After this data is decrypted, the following registry key is written to ensure persistence... HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Putty - %TEMP%\winopen.exe ... In order to maintain persistence, the malware will generate the following file in the startup folder... MY24 proceeds to execute a function that is responsible for generating the following path: %APPDATA%\Startup\wintasks.exe
After this data is decrypted, the following registry key is written to ensure persistence... HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Putty - %TEMP%\winopen.exe ... In order to maintain persistence, the malware will generate the following file in the startup folder... MY24 proceeds to execute a function that is responsible for generating the following path: %APPDATA%\Startup\wintasks.exe
It proceeds to decrypt an embedded resource object using the RC4 algorithm... Throughout the execution of this sample, numerous strings are decoded using a customized 94-character substitution table... All data received and sent by MY24 is encrypted using a 13-byte XOR key
The username and computer name are identified, and are written to a string of the following format: User name and System Name :- [Username]_[Computer Name]
2019 List current process network communication on the victim machine
The data portion of the received command will include one of the following commands: ... 2023 Enumerate processes
The following information is collected: Version of Microsoft Windows Username Computer name
The data portion of the received command will include one of the following commands: ... 2001 Get drive information 2002 List files | The data portion of the received command will include one of the following commands: ... 2005 Create file handle to append data 2006 Write appended data to previously created file handle 2007 Create file handle for reading data 2009 Read data from previously created file handle
BioData sends both GET and POST requests to the following URL: http://errorfeedback[.]com/MarkQuality455/developerbuild.php ... This particular sample attempts to connect to the following host for C2 operations... MY24 instance expects to receive a command initially from the remote server of userveblog.ddns[.]net on port 9832.
All communication is performed using raw sockets via a custom communication protocol.
The shellcode then proceeds to make a request to the following URL and download the response to ‘C:\Wins\cnh’. http://zmwardrobe[.]com/wp-sign Finally, the shellcode will execute this downloaded file via a call to WinExec.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously analyzed payload noted for infrastructure overlap with ArtraDownloader activity; both were observed using the same domain and InPage exploits.
A previously unknown backdoor downloaded by malicious InPage shellcode. It resolves and connects to a C2 domain over raw sockets, collects host information, supports file operations, process enumeration, shell spawning, and command execution, and encrypts communications with a 13-byte XOR key.
A previously unknown backdoor downloaded by an InPage exploit chain. It resolves and connects to a C2 domain over raw sockets, collects basic host information, encrypts communications with a 13-byte XOR key, and supports commands for reconnaissance, file operations, process management, and spawning an interactive cmd.exe shell.
Previously unknown backdoor downloaded by an InPage exploit. It connects to a C2 over raw sockets, encrypts traffic with a 13-byte XOR key, collects host information, supports file operations, process enumeration, network listing, and remote shell execution via cmd.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.