Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The file named Update is identified as the primary payload. It spreads to other targets, maintains persistence, uploads results to the attacker server, drops cache and .bisis, and uses cloud-detection logic.
The file named Update is identified as the primary payload. It spreads to other targets, maintains persistence, uploads results to the attacker server, drops cache and .bisis, and uses cloud-detection logic.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The Update file maintains persistence by modifying the crontab to schedule recurring tasks for Update, History, .b, and .c.
#!/bin/bash /bin/bash -c " $(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh) "
The binary ‘update’ is a sophisticated piece of a multi-stage dropper that employs advanced obfuscation techniques to hide malicious commands. The malware uses XOR-based encoding, Mersenne Twister PRNG, and complex mathematical operations to decode and execute system commands.
Diicot payloads use a modified UPX packer that changes the magic header from "UPX!" to "YTS\x99" and corrupts checksum information.
The Update payload drops two additional embedded malicious files; abc123 also contains a version of Update as an embedded binary payload.
It uses sudo to clear quarantine attributes from the downloaded file ... PS: “xattr” here is used to remove the “com.apple.quarantine” to remove the mark of the web.
The binary included a “guardrail” to detect virtual machines or analysis environments. It used system_profiler to check for signs of virtualisation (e.g., “QEMU”, “VMware”) ... If detected, it exited with code 100.
The .bisis scanner downloads an IP list, scans port 22 on remote machines for SSH banners, and looks specifically for responses indicating OpenSSH.
Update checks Linux distribution and version, while successful brute-force reports include CPU count, hostname, architecture, kernel version, and GPU availability.
The binary included a “guardrail” to detect virtual machines or analysis environments. It used system_profiler to check for signs of virtualisation (e.g., “QEMU”, “VMware”) ... If detected, it exited with code 100.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.