Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The other two RAT families observed in the campaign are the previously documented SpiceRAT and BloodAlchemy.
Another indicator that points to China-nexus is the use of an updated version of SpiceRAT, which is equipped to download and run executable binaries and arbitrary commands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
DriveSilkRAT ... run it through an in-memory .NET plugin system ... NodeEdgeRAT ... spanning command execution ... SpiceRAT ... equipped to download and run executable binaries and arbitrary commands.
It runs its command channel over trusted services like Google Drive, hides inside legitimately signed applications, and keeps its footprint deliberately small.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously documented remote access Trojan observed alongside other RAT families in the SilkParasite campaign targeting Central Asian government entities.
Remote access tool capable of downloading and executing binaries and arbitrary commands; cited as another China-nexus indicator in the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.