Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RatelS • msbtc.exe legitimate file used for Side-load • VERSION.dll executed via Side-Load • msbtc.dat Encoded Mofu Loader • Decrypt and execute the RatelS of the encapsulated payload • msbtc.cfg RatelS config file
RatelS (Ratel Master) ... msbtc.dat ○ エンコードされたMofu Loader ○ 内包したペイロードのRatelSを復号して実行する
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Slides on '2nd Stage PE Loader (Mofu Loader)' state 'API Hashingのアルゴリズム(ror 12)と利用するAPIが同じ' and compare GroundPeony and RatelS loaders.
The payload comparison slide states 'カスタムXOR + LZNT1で展開される2ndペイロード' for GroundPeony and RatelS.
Slides describe 'カスタムXORのアルゴリズムが同じ ○ sub + xor + add' and 'Custom xor + LZNT1' used to unpack second-stage payloads, with PE magic values removed.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access backdoor used by the Ratel Master cluster. It is delivered via DLL side-loading, with Mofu Loader decrypting and loading the payload. The malware uses RC4-protected stages and shows implementation similarities with HemiGate and PlugX, including communications, keylogging-related behavior, config structure, and module mapping.
A remote access trojan/backdoor delivered through DLL side-loading and a Mofu Loader stage. It uses RC4-decrypted components, in-memory loading, C2 communications, proxy handling, authentication logic, keylogging-related functionality, and structured configuration data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.