Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Malware in general uses the Process Explorer driver to conduct activities with kernel privileges, such as killing processes of detection mechanisms to evade detection or duplicating process handles for tampering.
some strings (such as amsi.dll and AmsiScanBuffer) are Base-64 encoded and AES-encrypted.
We also observed MalVirt samples evaluating whether they are executing within a virtual machine or an application sandbox environment.
detecting the VirtualBox and VMWare environments involves querying the registry keys HKEY_LOCAL_MACHINE\SOFTWARE\Oracle\VirtualBox Guest and HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc.\VMware Tools
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET malware loader distributed via malvertising that uses modified KoiVM-based virtualization, AMSI bypass, VM/sandbox checks, invalid code-signing lures, and the Process Explorer driver for process termination. It stages downstream payloads including Formbook-family malware.
A tool reported by SentinelOne that uses the same vulnerable Process Explorer driver to disable security products before delivery of a final payload.
A tool reported by SentinelOne that uses the same vulnerable Process Explorer driver to disable security products prior to deployment of a final payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.