Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
IT 기업에서 발견된 악성 winhttp.dll 은 파일리스(Fileless) 악성코드를 메모리에 생성 ... 실제 악성 행위(자료 유출, 악성코드 생성, C2 통신 등)는 메모리에 생성된 파일리스 악성코드가 담당
9 distinct techniques documented for this family, organized by ATT&CK tactic.
IT 기업에서 발견된 악성 winhttp.dll 은 파일리스(Fileless) 악성코드를 메모리에 생성... 실제 악성 행위(자료 유출, 악성코드 생성, C2 통신 등)는 메모리에 생성된 파일리스 악성코드가 담당합니다.
the Sophos MDR team observed the OneDriveStandaloneUpdater.exe process conducting scanning with the SMB protocol to map online hosts within the customers’ environment. The threat actor also scanned for Remote Desktop Protocol and Windows Remote Management (WinRM) hosts
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.