Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Next in DeathStalker’s intricate VileRAT infection chain comes VileDropper. It is an obfuscated JavaScript file that mainly drops and schedules the execution of the next stage: VileLoader.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Back in the summer of 2020, DeathStalker’s VileRAT initial infection consisted in spear-phishing emails sent to foreign exchange companies... More recently... the initial infection vector is still a malicious message: a Word document (DOCX) is sent to targets via email.
the DOTM-embedded macro silently gathers information about security products that are installed on the target computer (using WMI)... VileDropper... gathers additional data on the targeted environment (using WMI).
VileDropper... schedules a task to run VileLoader 35 to 65 seconds later, then indefinitely every three hours and 45 minutes... VileRAT functionalities include... Setting up persistence using scheduled tasks.
The malicious DOTM remote templates leverage the VBA stomping technique to conceal the code of an embedded macro... the DOTM-embedded macro silently gathers information... decodes and drops files, then ultimately executes a malicious obfuscated JavaScript (JS) backdoor we called VileDropper.
It is lightly obfuscated, as most text strings are XOR-encoded... VileDropper is an obfuscated JavaScript file... the first stage of VileRAT has been obfuscated at the Python bytecode-level, with the intention of breaking existing decompilers.
a Windows shortcut file masquerading as a PDF... using a renamed copy of the “WScript” interpreter (“msdcat.exe” or “msgmft.exe” in the “%APPDATA%” folder)... files are placed under a seemingly legitimate common folder in “%APPDATA%”.
the DOTM-embedded macro finally triggers VileDropper’s execution, using a renamed copy of the “WScript” interpreter (“msdcat.exe” or “msgmft.exe” in the “%APPDATA%” folder)
the DOTM-embedded macro silently gathers information about security products that are installed on the target computer... VileDropper: gathers additional data on the targeted environment... The JSON that is passed to the C2 server can be broken down as follows... host, uname, Windows version.
The useful information is stored as a JSON document... and set as a cookie value in the HTTP request... VileLoader stage 2 sends an HTTP POST request with a cookie whose value is a XORed JSON dictionary.
179 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.