Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE Defense Evasion: T1027 – Obfuscated Files or Information
The loader queries display device information via EnumDisplayDevicesA... decrypts a hardcoded list of known hypervisor and analysis-environment display device strings... If any match is detected, the loader silently terminates execution.
The stealer begins its execution by retrieving the MachineGuid value from HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
It then proceeds to enumerate all active processes on the system, collecting the Process ID, Session ID, Process Name, and corresponding command-line arguments.
After obtaining the session ID... this includes a broad set of system attributes such as the current timestamp, GPU model, RAM and CPU specifications, MachineGuid, and other environment details.
The loader queries display device information via EnumDisplayDevicesA... decrypts a hardcoded list of known hypervisor and analysis-environment display device strings... If any match is detected, the loader silently terminates execution.
75 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing payload delivered by OnionDrop.
An infostealer delivered by OnionDrop in earlier campaign waves and one of the confirmed final payloads tracked in the same activity cluster.
A previously unreported information stealer that harvests browser credentials, cookies, payment data, crypto wallet data, password manager data, VPN configurations, FTP credentials, SSH keys, messaging app artifacts, and other host information, then exfiltrates the data in an in-memory ZIP encrypted with ChaCha20 and authenticated with HMAC-SHA256 over HTTP POST requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.