Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After establishing persistence, the stager retrieves the main DenoRAT malware payload. DenoRAT is a remote access trojan written entirely in Deno-JavaScript.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Then, the MSI file writes and executes a Windows batch file. This batch file launches an artificial intelligence-generated PowerShell script named Griffin20.ps1.
DenoRAT ultimately functioned as a loader for NightshadeC2, receiving a task from the C2 that launched a Python-based in-memory loader to decrypt and execute the NightshadeC2 RAT/infostealer payload.
Once Deno is available, the script runs it with full permissions using deno run -A to fetch and execute the remote launcher.
The attack begins with a ClickFix-style social engineering lure. Specifically, the attackers trick a victim into executing a command via the Windows Run prompt. | Specifically, the attackers trick a victim into executing a command via the Windows Run prompt. This command downloads and runs a Microsoft Installer (MSI) file.
This secondary stager establishes persistence by creating a new registry value in the CurrentVersion Run key.
It achieves this by injecting a malicious DLL into active Chromium browser processes.
It achieves this by injecting a malicious DLL into active Chromium browser processes.
The attackers use Obfuscator.io to hide the secondary stager code. This obfuscation greatly complicates the analysis process for incident responders.
It achieves this by injecting a malicious DLL into active Chromium browser processes.
It achieves this by injecting a malicious DLL into active Chromium browser processes.
To prepare for injection, it enumerates running processes matching the browser list below using the Windows APIs CreateToolhelp32Snapshot , Process32First , and Process32Next .
DenoRAT communicates with its command-and-control server using regular HTTP polling.
DenoRAT communicates with its command-and-control server using regular HTTP polling.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Deno/JavaScript-based remote access trojan that uses Deno FFI to call native Windows APIs, polls C2 over HTTP, gathers system information, steals browser and extension data, captures screenshots, and attempts App-Bound Encryption bypass via DLL injection into Chromium processes.
A Deno/JavaScript-based remote access trojan with stealer and loader capabilities. It supports HTTP/WebSocket C2, persistence, host registration, command execution, PTY sessions, VNC-style remote control, file operations, screenshot capture, system profiling, browser and wallet theft, and can load NightshadeC2 in memory via a PowerShell-delivered Python loader. It also contains Chromium App-Bound Encryption bypass functionality using DLL injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.