Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
There's also Francesca Maria Occhionero, who along with her brother was arrested in January 2017 and charged with disseminating a malware program called EyePyramid that was used to hack the email accounts of Italian politicians, Vatican cardinals and the president of the European Central Bank.
The sample is written in .Net and it is heavily obfuscated... The author paid attention to hide the core functionalities by using either known .Net obfuscators or cryptography to hide crucial information such as URLs, email addresses and credentials.
Also the attackers relied on executable files masking the extension of the file with multiple spaces.
After authentication, the agent downloads the resource and writes it to the disk in encrypted form. Next, the file is read and decrypted, with the decryption key being used as the temporary filename. Finally, the file is deleted.
The sample cannot be debugged, and it does not run inside virtual machines due to several and sometimes trivial (but effective) anti-debugging and anti-vm checks... If this is less than 46.5 GB and the operating system is Windows XP, this is not a valid environment.
Additionally in the code there is also support for Active Directory and LDAP. The code concerning Active Directory lists the administrative members of the domains and it checks if the current user is in this list.
The sample cannot be debugged, and it does not run inside virtual machines due to several and sometimes trivial (but effective) anti-debugging and anti-vm checks... If this is less than 46.5 GB and the operating system is Windows XP, this is not a valid environment.
The sample interacts with Command and Control servers and can download additional files. This C&C communication is authenticated with a username and password. | Exfiltration The exfiltration is done mainly via email and partially via WebDAV and HTTP. Regarding emails, they are sent via SMTP protocol... The message is then uploaded to the IMAP server in a specific folder.
218 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware program reportedly used to hack the email accounts of Italian politicians, Vatican cardinals, and the president of the European Central Bank.
A .NET malware family used to target Italian celebrities and politicians. It is heavily obfuscated, establishes persistence via Run/RunOnce registry keys, performs anti-debugging and anti-VM checks, disables or interferes with security software and UAC, creates firewall exceptions, communicates with C2 infrastructure, downloads additional files, and exfiltrates data primarily via SMTP/IMAP email attachments and also via WebDAV and HTTP.
A low-sophistication spear-phishing-delivered espionage malware used to compromise victims’ Windows systems, grant access to resources on the victim computer, and exfiltrate stolen data to attacker-controlled email accounts and C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.