Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A remote access Trojan named Parallax is being widely distributed through malicious spam campaigns that when installed allow attackers to gain full control over an infected system.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to the researcher’s observations, AsyncRAT, NetWire, WSH RAT, and Parallax appears to be the group’s top favorites being pushed most often in malicious messages.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
A typical TA2541 attack chain starts with sending an email that is usually related to transportation (e.g. flight, aircraft, fuel, yacht, charter, cargo) and delivers a malicious document.
In the next step, the adversary executes PowerShell into various Windows processes and looks for available security products by querying the Windows Management Instrumentation (WMI).
A scheduled task is used to establish persistence for the PARALLAX RAT... creating a scheduled task to run Msidb.exe using Component Object Model (COM).
If executed, PowerShell pulls an executable from a text file hosted on various platforms such as Pastetext, Sharetext, and GitHub.
The macro parses the embedded paragraph text on page three of the lure document... [and] uses the CreateObject function to create the required objects and download each of the malware components.
A scheduled task is used to establish persistence for the PARALLAX RAT... creating a scheduled task to run Msidb.exe using Component Object Model (COM).
The malware extracts a configuration structure from the stenographically-obfuscated PNG that contains the next PARALLAX loader stage and the final payload.
The malicious code is heavily obfuscated and leverages dynamic API resolution... retrieve library addresses using the CRC32 checksum hash of the requested library name... [and] builds its own import table.
The loader uses the Heaven’s Gate technique and performs injection in the suspended cmd.exe process... [and] creates a suspended cmd.exe process and injects the NETWIRE payload and the last PARALLAX stage.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PARALLAX is explicitly described as a malware loader. The referenced Python utility extracts payloads from PARALLAX samples; the content provides no further payload behavior or targeting details.
A modular backdoor/loader used in multi-stage maldoc campaigns. It uses DLL side-loading, dynamic API resolution, direct system calls, Heaven's Gate, process injection, steganographically concealed PNG payloads, UAC bypass, and scheduled-task persistence. It can load NETWIRE or PARALLAX RAT payloads for remote access.
A commodity RAT used by TA2541 as a payload in email-based intrusion campaigns to gather information from compromised hosts.
Commodity RAT used by TA2541 in phishing-driven campaigns to gain remote control and collect information from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.