Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It also uses a COFF Loader component to execute Beacon Object Files directly in memory and SilentMoonwalk to forge call stacks and make monitored operations harder to trace.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
“Malware authors use this ambiguity to lie. They either craft trampoline stack frames through legitimate modules to hide calls originating from malicious code, or they coerce stack walking into predicting different return addresses than those the CPU will execute.”
Before that thread executes a single instruction, we replace its stack with a fake one built from real frames in real signed DLLs. When the kernel callback fires, it reads the fake stack and sees a chain of legitimate Windows frames.
For call stacks, these include: image_rop No call instruction preceded an entry in the call stack.
Malware authors use this ambiguity to lie. They either craft trampoline stack frames through legitimate modules to hide calls originating from malicious code, or they coerce stack walking into predicting different return addresses than those the CPU will execute.
Some EDRs register kernel callbacks via ObRegisterCallbacks that fire when a process handle is opened. At that moment they capture the call stack of the thread making the call. If that stack shows a return address in dynamically allocated memory without a backing DLL on disk, they alert
Some EDRs register kernel callbacks via ObRegisterCallbacks that fire when a process handle is opened. At that moment they capture the call stack of the thread making the call. If that stack shows a return address in dynamically allocated memory without a backing DLL on disk, they alert
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A call-stack spoofing tool used by SparroWocky to forge call stacks, hindering monitoring and tracing of malicious operations.
A call-stack spoofing/evasion tool variant integrated into SparroWocky to conceal execution associated with hooked routines.
A call-stack spoofing tool/technique integrated in variant form into SparroWocky for defense evasion.
A tool/research implementation for dynamic call stack spoofing on Windows, used to evade or confuse EDR visibility by falsifying stack traces and masking the true source of sensitive API calls.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.