Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The starting point is typically a phishing email with a malicious attachment... The first infection scheme uses a RAR archive with an executable file masquerading as a document... In the second case, the RAR archive contains a Microsoft Office document with a macro that serves as a dropper.
The following examples illustrate the execution chains observed on remote hosts: wmiprvse.exe -secured -Embedding -> cmd.exe / C mshta.exe ...
Злоумышленники всё реже используют "классические" вредоносные программы и опираются на легитимные утилиты удалённого управления, PowerShell-скрипты (T1059.001) и облачные сервисы.
it first uses cmd.exe and output redirection to drop a JavaScript file named “UserCacheHelper.lnk.js” onto the disk...
the launch of csc.exe... indicates that PowerTaskel has received a task to load a shellcode, which it accomplishes using an auxiliary DLL. The primary function of this DLL is to copy the shellcode into allocated memory.
The shellcode... contains an obfuscated Mythic agent... the PowerModul code is embedded in the “UserCache.ini” file as a Base64-encoded string... request payloads are... encoded using XOR... and then converted to Base64.
PowerTaskel... sending information about the targeted environment to a C2 server in the form of a “checkin” message... Once launched, PowerTaskel interacts with its C2 server and executes standard commands to gather information about the system and environment.
When accessing the C2, PowerModul appends an infected system identifier string to the C2 URL... The response from the C2 is in XML format...
PowerModul is a PowerShell script capable of receiving and executing additional PowerShell scripts from the C2 server... Initially, it was used to download and launch the PowerTaskel implant... user.txt is another PowerShell script whose task is to extract a payload from a hardcoded address and execute it.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom agent/backdoor used by GOFFEE via the Mythic framework for command-and-control and persistence.
Модульный агент платформы Mythic, упомянутый как связанный инструмент в контексте использования Mythic другими APT-группами.
Непубличный агент для Mythic на PowerShell. Выполняет check-in, получает задачи с C2 и исполняет произвольные PowerShell-команды и скрипты; использовался также для загрузки и запуска бинарного Mythic-агента, повышения привилегий и горизонтального перемещения.
A non-public PowerShell Mythic agent that checks in to C2, receives tasks, and executes arbitrary PowerShell scripts and commands. It is also used for privilege escalation, payload delivery, and loading a binary Mythic agent for lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.