Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
조건이 맞는 컴퓨터의 경우에는 내부에 암호화된 코드를 XOR 0x55 키로 복호화한 후 'conhost.exe' 파일명으로 생성해 실행하게 됩니다. 'conhost.exe' 파일의 경우가 바로 AOL 메신저로 통신을 하는 기능을 수행하게 됩니다.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.