Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Samples typically weigh between 700 and 950 MB. That heft comes from a massive, padded overlay appended to the file. This bloat is deliberate. Many antivirus and EDR tools skip deep scanning of very large files to protect performance.
Attackers spread it through two main channels. The first is fake “cracked” software.
Allocate an RWX memory region using VirtualAlloc with MEM_COMMIT | MEM_RESERVE and PAGE_EXECUTE_READWRITE flags... Map the decoded payload into the allocated memory region... Transfer execution to the final payload using Go’s syscall.Syscall.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as related coverage about a loader delivering infostealers.
A Golang-based loader that uses oversized binaries with massive padded overlays to evade scanning limits and detection, then reconstructs and executes payloads in memory without touching disk. It is distributed via fake cracked software and malicious traffic distribution systems, and primarily delivers infostealers.
A Go-based malware loader that evades scanning by inflating its PE overlay to an unusually large size and delivers infostealer payloads entirely in memory, avoiding disk-based detection.
A Go-based in-memory PE loader that decodes an embedded payload, manually maps it into RWX memory, resolves imports and relocations, and transfers execution to the payload. Its main evasion feature is a massive appended PE overlay that inflates file size to hinder scanning and sandbox submission.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.