Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Techniques / Sub Techniques Acquire Infrastructure - Virtual Private Server
Techniques / Sub Techniques ... Develop Capabilities - Malware ... The Deimos implant was first reported in 2020 and has been in active development
Techniques / Sub Techniques ... Develop Capabilities - Malware, Code Signing Certificates ... lure file samples ... were signed with a digital certificate
The final persistence artifact is a .LNk file that is placed in the user's StartUp directory... The next function script will create two registry keys that provide a Windows shell handler... Techniques / Sub Techniques ... Boot or Logon Autostart Execution - Registry Run Keys / Startup Folder
The final persistence artifact is a .LNk file that is placed in the user's StartUp directory... The next function script will create two registry keys that provide a Windows shell handler... Techniques / Sub Techniques ... Boot or Logon Autostart Execution - Registry Run Keys / Startup Folder
The malware employs multiple layers of complex obfuscation and encryption techniques... employing advanced analysis countermeasures to frustrate analysis.
Hunting C2/Adversaries Infrastructure with Shodan and Censys ... My research Cobalt Strike C2 Metasploit/MSF Covenant C2 Deimos C2 Posh C2 Brute Ratel C4 Mythic C2 Sliver C2 ... Night Hawk C2 NimPlant C2 ShadowPad C2 Infrastructure Async Rat C2 Infrastructure Meterpreter C2 Infrastructure
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.