Skip to main content
Mallory
Back to malware
Malware

Overlord C2

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

1 technique
T1070Indicator RemovalEvidence1

the North Koreans added three custom modules: browserlogin... companywallet... and cleanup (anti-forensic removal of workspace artifacts).

Credential Access

4 techniques
T1056.002GUI Input CaptureEvidence1

using a second embedded Mach-O binary that displays a fake system dialogue and prompts the user to enter their password... It, however, uses Zenity, a standard GTK dialog tool, to create a prompt and collect victim credentials.

T1555Credentials from Password StoresEvidence1

the malware modifies keychain access-control lists... before extracting Safe Storage keys... This backdoor attempts to steal passwords from GNOME Keyring

T1555.003Credentials from Web BrowsersEvidence1

collects a ton of credentials across Chromium and Firefox browsers, steals cookies from Chrome/Edge/Brave

T1649Steal or Forge Authentication CertificatesEvidence1

For this campaign, the North Koreans added three custom modules: browserlogin (Chrome and Firefox credential theft)...

Collection

2 techniques
T1056.002GUI Input CaptureEvidence1

using a second embedded Mach-O binary that displays a fake system dialogue and prompts the user to enter their password... It, however, uses Zenity, a standard GTK dialog tool, to create a prompt and collect victim credentials.

T1560Archive Collected DataEvidence1

collects wallet extension data, browser profile artifacts, and standalone wallet directories, compressing them into a ZIP and uploading them to the C2 server

Command and Control

1 technique
T1219Remote Access ToolsEvidence1

The Linux and macOS attacks use a native Go binary that connects to the command-and-control (C2) infrastructure as a persistent remote access trojan (RAT). The Linux and macOS binaries are based on the open-source Overlord C2 framework

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.