Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
"These included a raw disk wiper that overwrites physical disks and destroys partition information... and a multipass secure wiper ... that repeatedly overwrites files to hinder forensic recovery."
один из модулей малвари основан на коде шифровальщика Crucio: он шифрует файлы, добавляет к ним расширение .candy и меняет обои на рабочем столе. При этом малварь не сохраняет ключ и не оставляет записку с требованием выкупа
отдельная команда отключает среду восстановления Windows и провоцирует «синий экран смерти», после чего устройство перестает загружаться
A raw disk wiper that overwrites the physical drive and wipes the partition table (the map of how the disk is laid out) before rebooting.
Другой компонент представляет собой переписанный на Go вайпер FlockWiper. Он многократно перезаписывает системный диск, используя разные шаблоны. | Эта версия использует Windows Management Instrumentation (WMI) для идентификации системного раздела Windows, удаляет таблицу разделов, а затем перезаписывает содержимое диска, уничтожает метаданные и перезагружает систему.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based Windows backdoor that provides persistent access, disguises C2 via RabbitMQ, stores task results in Redis, exfiltrates stolen data through MinIO, can encrypt files with a .candy extension, and includes multiple disk-wiping capabilities designed to prevent recovery.
A Golang-based full-featured backdoor that provides remote access, system profiling, VNC-based control, file exfiltration, file encryption using the .candy extension, and two disk-wiping modules capable of permanently rendering systems unrecoverable. It uses RabbitMQ for tasking, Redis for state management, and MinIO for exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.