Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The GET request to “load.php” delivers the following PowerShell code... The PowerShell script above downloads a .NET executable from a remote URL ... and executes the Main method
var _0x15e0e2 = new ActiveXObject ( _0xfe1844 [ 'EvXLb' ]); ... var _0x341166 = new ActiveXObject ( _0xfe1844 [ 'PNbxJ' ]);
The code depicted in Figure 3 demonstrates how to create and manipulate a suspended process in Windows, inject code into it, and then execute that code. CreateProcess ... VirtualAllocEx ... WriteProcessMemory ... QueueUserAPC ... ResumeThread
QueueUserAPC : Queues the execution of the injected code to the main thread of the suspended process. ResumeThread : Resumes the thread, causing the injected code to execute.
Various variables are declared first and a defined value is assigned to the variables... The variable MlueKUrTONhlBYgGdDIH... is passed to the decodeURIComponent function
The code depicted in Figure 3 demonstrates how to create and manipulate a suspended process in Windows, inject code into it, and then execute that code. CreateProcess ... VirtualAllocEx ... WriteProcessMemory ... QueueUserAPC ... ResumeThread
QueueUserAPC : Queues the execution of the injected code to the main thread of the suspended process. ResumeThread : Resumes the thread, causing the injected code to execute.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet used to target Mexican taxpayers through impersonation of official government portals.
Botnet targeting users of government services in Mexico by impersonating official tax-related portals; infrastructure includes payload delivery, C2, hosting control panels, and a central server for data collection and management. Operators likely monetize access and may collaborate with the broader cybercriminal ecosystem.
Named malware/tool family listed as detectable via favicon hash hunting of exposed infrastructure.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.