Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
P8LOADER is a newly discovered x64 Windows loader that is used to execute a PE from a file or from memory.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The unsigned DLL (dbg.config) contained DONUTLOADER shellcode which it attempted to inject into sessionmsg.exe... SPECTRALVIPER can load and inject executable files... command handlers include InjectShellcodeInProcess, CreateProcessAndInjectShellcode, InjectPEInProcess, and CreateProcessAndHollow.
SPECTRALVIPER is heavily obfuscated using control-flow flattening and custom AES string decryption; P8LOADER also obfuscates strings.
SysInternals ProcDump was renamed to windbg.exe and abused (-md) as a LOLBAS to load an unsigned malicious DLL.
The unsigned DLL (dbg.config) contained DONUTLOADER shellcode which it attempted to inject into sessionmsg.exe... SPECTRALVIPER can load and inject executable files... command handlers include InjectShellcodeInProcess, CreateProcessAndInjectShellcode, InjectPEInProcess, and CreateProcessAndHollow.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An obfuscated x64 PE loader used alongside SPECTRALVIPER to stage payloads in memory as part of the intrusion chain.
A newly discovered x64 Windows PE loader that can load executables from file or memory, create a new thread at the PE entry point, redirect STDOUT to its logging system, and hook imported APIs to log calls over a named pipe.
A C++ Windows x64 PE loader that maps and executes PE payloads from disk or memory using a classic PE-loading routine. It redirects payload standard output to its logging mechanism and hooks imported APIs to log calls through a randomly named pipe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.