GollopDevest is a .NET malware component used as an intermediate downloader/loader stage in multi-step Windows infection chains that ultimately deliver additional payloads, including Amatera Stealer. It has been observed in campaigns themed around fake game, mod, crack, and software downloads, where victims are presented with a decoy installer while the malicious chain executes in the background. In the documented execution flow, GollopDevest is loaded after earlier stages abuse MSBuild and a trojanized .NET component to reconstruct and execute successive payloads.
A defining characteristic of GollopDevest is its use of the EtherHiding technique to obtain command-and-control information from blockchain-related infrastructure rather than embedding conventional network indicators directly in the sample. It retrieves an encrypted command-and-control destination through an Ethereum JSON-RPC call and then uses that information to download the next stage. This design complicates infrastructure discovery and blocking and aligns with tradecraft intended to improve resilience and evasion.
GollopDevest has been associated with campaigns that use fake software distribution channels and with activity linked to ClickFix-style delivery chains. Within the observed infection sequence, it functions as a downloader/loader stage rather than the final payload, enabling subsequent components such as anti-analysis modules and the final infostealer. High-confidence reporting places it on Windows systems and supports its role in post-compromise payload retrieval and execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Déchiffre une archive ZIP (XOR + Base64) ... La DLL implémente un bytecode personnalisé avec 23 opcodes, déchiffrement multi-clés XOR
La DLL implémente un bytecode personnalisé avec 23 opcodes, déchiffrement multi-clés XOR, résolution d’API par hashing
Le fichier BAT active MSBUILDENABLEALLPROPERTYFUNCTIONS=1 Exécute MSBuild.exe avec Nancy.csproj comme projet
Reads the config data/.GEg and decrypts it using Base64 decoding and XOR... XOR-decrypts data/j3lpTcg7kBRN.E3 using the key A50YyY1 to obtain the ZIP... During project evaluation, a malicious MSBuild property function hex-decodes and reflectively loads the next DLL stage.
The malware then downloads the next stages of the attack from that server... The encrypted C2 domain is obtained using an Ethereum JSON-RPC eth_call request to bsc-dataseed.binance.org | That malicious component uses a technique called EtherHiding to locate its command-and-control (C2) server. Instead of storing the C2 address directly inside the malware, the attackers hide it in data stored on a public blockchain.
uses a technique called EtherHiding to locate its command-and-control (C2) server. Instead of storing the C2 address directly inside the malware, the attackers hide it in data stored on a public blockchain.
le domaine C2 chiffré est récupéré via un appel JSON-RPC Ethereum ( eth_call ) vers bsc-dataseed.binance.org
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DLL .NET chargeur utilisée dans la chaîne d’infection, récupérant un domaine C2 chiffré via la technique EtherHiding à travers un appel JSON-RPC Ethereum afin de compliquer l’identification et le blocage de l’infrastructure C2.
A .NET downloader/loader stage that uses EtherHiding via blockchain data to retrieve its C2 and download additional payloads.
A .NET downloader/loader stage that retrieves its C2 via EtherHiding using blockchain data, then downloads additional payloads. The name is also used for a later loader DLL in the same chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.