Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence – Schedule Task The Schtasks method creates a scheduled task using the Windows command line.
When executed, the malware drops two executable files in different folders. These files are configured to run automatically via the Task Scheduler, ensuring they remain persistent
Persistence – Schedule Task The Schtasks method creates a scheduled task using the Windows command line.
When executed, the malware drops two executable files in different folders. These files are configured to run automatically via the Task Scheduler, ensuring they remain persistent
The below AntiScan method attempts to bypass Windows Defender’s scans by adding exclusions to the Defender registry settings.
MITRE ATTACK FRAMEWORK Sr. No. 2 Persistence T1505 Server Software Component
Persistence – Schedule Task The Schtasks method creates a scheduled task using the Windows command line.
When executed, the malware drops two executable files in different folders. These files are configured to run automatically via the Task Scheduler, ensuring they remain persistent
MITRE ATTACK FRAMEWORK Sr. No. 2 Persistence T1547 Boot or Logon Autostart Execution
Persistence – Registry Value changes The HKCU method updates a specific registry key under HKEY_CURRENT_USER to store a given Name.
The below AntiScan method attempts to bypass Windows Defender’s scans by adding exclusions to the Defender registry settings. It modifies the registry paths dynamically (by removing obfuscation placeholders like “button” and “UIUSS”).
MITRE ATTACK FRAMEWORK Sr. No. 4 Defense Evasion T1027.004 Compile After Delivery
MITRE ATTACK FRAMEWORK Sr. No. 4 Defense Evasion T1070 Indicator Removal
MITRE ATTACK FRAMEWORK Sr. No. 4 Defense Evasion T1140 Deobfuscate/Decode Files
Anti VM: The RunAntiAnalysis method checks if the program is running in a virtual machine (VM)... If no objects are found ... the program terminates with exit code 240, acting as an anti-analysis mechanism.
MITRE ATTACK FRAMEWORK Sr. No. 5 Discovery T1033 System Owner/User Discovery
It uses Windows API calls (CreateToolhelp32Snapshot, Process32First, Process32Next) to enumerate processes and check if their executable names match the specified targets.
This method queries system information (Win32_CacheMemory) to detect the presence of memory objects indicative of a physical machine.
The developer behind the ransomware is utilizing AES encryption to lock various file types, including those with extensions such as “.csv”, “.txt”, and “.php”.
Anti VM: The RunAntiAnalysis method checks if the program is running in a virtual machine (VM)... If no objects are found ... the program terminates with exit code 240, acting as an anti-analysis mechanism.
This method queries system information (Win32_CacheMemory) to detect the presence of memory objects indicative of a physical machine.
The below Block method continuously monitors running processes to detect and terminate specific target processes like “Taskmgr.exe”, “ProcessHacker.exe”, and “procexp.exe”.
It enables critical process handling (BSOD), performs anti-defender scans...
The below Block method continuously monitors running processes to detect and terminate specific target processes like “Taskmgr.exe”, “ProcessHacker.exe”, and “procexp.exe”. | ASMI (Antimalware Scan Interface) Bypass: The code below searches for the “amsi.dll” module... modify specific memory regions related to “AmsiScanBuffer”
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.