Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Its PowerShell command can fetch both a randomly named 7-Zip program and a randomly named payload, or download the payload directly.
ErrTraffic begins after someone reaches a compromised WordPress website. The injected JavaScript does not contain the final destination in clear text.
This includes resolving LdrLoadDll, which loads bcrypt.dll while bypassing the more commonly hooked LoadLibrary call.
Instead of exploiting a software flaw, the page tells a visitor to copy and paste a supposed fix, often into the Windows Run box or PowerShell. | The campaign, tracked as ErrTraffic, turns hacked WordPress sites into launch points for fake verification prompts that persuade visitors to run harmful Windows commands. The trick is known as ClickFix.
Four-stage unpack chain. Custom byte-pair decoding, Xpress Huffman decompression, AES-256-CBC with rotating key context, ending in Donut shellcode.
Stack-string construction, dynamic API resolution via LdrGetProcedureAddress, API hammering, and display device enumeration defeat both static and dynamic analysis at every stage.
The malware combines stack-based strings with custom decryption logic to reconstruct sensitive strings at runtime, defeating static detection.
A legitimate Adobe-signed executable, setup.exe (originally named AcroBroker.exe), sideloads the malicious dependency named sqlite.dll.
The loader employs advanced evasion techniques, including DLL sideloading, layered decoding and decryption, dynamic API resolution, anti-analysis mechanisms, and shellcode execution through Windows Thread Pool callbacks...
The encoded contents pass through a custom decoding routine ... before being handed to subsequent decryption and decompression stages.
ZIP archive paired with a legitimate Adobe-signed executable initiates execution through sideloading.
The loader employs advanced evasion techniques, including DLL sideloading, layered decoding and decryption, dynamic API resolution, anti-analysis mechanisms...
Before executing its malicious logic, the malware queries the display device name through EnumDisplayDevicesA.
The malware avoids this by spawning a separate thread, waiting briefly via a short sleep interval, and returning from DllMain with a value of 1.
Before executing its malicious logic, the malware queries the display device name through EnumDisplayDevicesA.
The loader employs advanced evasion techniques, including DLL sideloading, layered decoding and decryption, dynamic API resolution, anti-analysis mechanisms...
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OnionDrop is described as a payload family using DLL side-loading to hide behind legitimate programs, with related activity involving a Node.js backdoor using Tor for command-and-control.
A sophisticated multi-stage malware loader used to deliver credential-stealing payloads at scale. It uses DLL sideloading, layered decoding and decryption, dynamic API resolution, anti-analysis mechanisms, and shellcode execution via Windows Thread Pool callbacks to evade detection and complicate analysis.
A four-stage, payload-agnostic loader delivered via DLL sideloading using a legitimate Adobe-signed executable. It uses custom byte-pair decoding, Xpress Huffman decompression, AES-256-CBC decryption with rotating key material, anti-analysis checks, dynamic API resolution, API hammering, and Thread Pool callback abuse to execute final shellcode and deliver downstream payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.