Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Contents of the BAT file: @echo off ... cmd.exe /c ...
In this case, the extracted BAT file was executed using the following command: forfiles.exe ... /c "cmd /c ren @file TP2hppNk5.bat && call TP2hppNk5.bat"
Once installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild... Executes MSBuild.exe with Nancy.csproj as its project file. During project evaluation, a malicious MSBuild property function hex-decodes and reflectively loads the next DLL stage.
The .NET DLLs are heavily obfuscated using control flow flattening, indirect calls through calli / ldftn, string encryption with several algorithms, junk code, dead code, and fake strings such as URL paths.
Resolves APIs using API hashing and GetDelegateForFunctionPointer.
The victim may see what appears to be a normal game or software installer while the malware runs silently in the background... By hiding malicious code inside software associated with gaming, attackers can make their downloads appear more believable.
Once installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild... Executes MSBuild.exe with Nancy.csproj as its project file. During project evaluation, a malicious MSBuild property function hex-decodes and reflectively loads the next DLL stage.
Reads the config data/.GEg and decrypts it using Base64 decoding and XOR... XOR-decrypts data/j3lpTcg7kBRN.E3 using the key A50YyY1 to obtain the ZIP.
Launches the payload using forfiles.exe... Executes MSBuild.exe with Nancy.csproj as its project file.
Calls sys_config.is_sandboxed() and exits if a sandbox is detected.
Relaunches itself in a hidden or headless console: "C:\WINDOWS\System32\conhost.exe" --headless cmd.exe /c
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage loader distributed via fake game/software downloads. It abuses the legitimate Ren'Py engine, decrypts embedded archives and configs, extracts payloads to TEMP, removes Mark-of-the-Web, launches via forfiles/MSBuild, and ultimately delivers follow-on malware including stealers.
A multi-stage loader distributed via fake game/software downloads. It abuses the legitimate Ren'Py engine to hide malicious code, decrypts embedded payloads, uses MSBuild to execute further stages, performs sandbox checks, removes Mark-of-the-Web protections, and can deliver varying final payloads including stealers and other loaders.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.