Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the use of a new Python-scripted Remote Access Trojan (RAT) Nocturnus dubbed PyVil RAT. PyVil RAT possesses different functionalities, and enables the attackers to exfiltrate data, perform keylogging and the taking of screenshots, and the deployment of more tools such as LaZagne in order to steal credentials.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Unlike previous versions where the malware used the Run registry key for persistence, in this new version, a scheduled task named “Dolby Selector Task” for ddpp.exe is created instead.
The PyVil RAT has several functionalities including: Keylogger Running cmd commands Taking screenshots
The Python code inside the py2exe is obfuscated with extra layers, in order to prevent decompilation of the payload using existing tools.
In Cybereason, we see the attempted credential dump by the payload.
PyVil RAT possesses different functionalities, and enables the attackers to exfiltrate data, perform keylogging and the taking of screenshots
The main goal of the group is to spy on its infected targets and steal information such as passwords, documents, browser cookies, email credentials and more.
Collecting information such as: Anti-virus products installed USB devices connected Chrome version
PyVil RAT’s C2 communications are done via POST HTTP requests and are RC4 encrypted using a hardcoded key encoded with base64.
PyVil RAT possesses different functionalities, and enables the attackers to exfiltrate data, perform keylogging and the taking of screenshots, and the deployment of more tools such as LaZagne in order to steal credentials.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-scripted remote access trojan compiled with py2exe that supports keylogging, screenshot capture, command execution, SSH shell access, data exfiltration, host reconnaissance, and downloading additional Python modules or executables such as credential theft tools.
A Python-based remote access trojan compiled with py2exe. It supports keylogging, screenshot capture, command execution, SSH shell access, downloading additional Python modules or executables, credential and cookie theft, and host reconnaissance, with RC4-encrypted HTTP POST C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.