Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-60137 is an SQL injection vulnerability in WordPress Core that allows an attacker to manipulate database queries and access data that should not be exposed. As a standalone flaw, it can be exploited only by an authenticated user. However, it becomes reachable without authentication when chained with CVE-2026-63030... In a chained exploit, the two flaws allow an unauthenticated attacker with no login credentials to gain full RCE on a default WordPress install. | In one case, we watched a threat actor repeatedly attempt to pull down Overlord RAT, a Golang-based remote access Trojan.
CVE-2026-63030 is a critical REST API batch-route confusion bug... When chained together, they can wreak havoc on any organization using a vulnerable WordPress version because they allow unauthenticated RCE.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Golang-based remote access Trojan that attackers attempted to download onto compromised WordPress systems for further access and compromise.
A Golang-based remote access trojan that attackers attempted to download onto compromised WordPress systems for further post-exploitation access.
A remote access trojan used in a tax-themed phishing campaign delivered via a malicious VHDX image, with DLL sideloading, in-memory shellcode execution, and layered anti-analysis techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.