Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
TELESHIM and MIXEDKEY used heavy code obfuscation techniques leveraging control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates to hinder reverse engineering.
The final payload is encrypted using two layers of XOR encryption... MIXEDKEY decrypts the payload and reflectively loads it.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 64-bit Windows reflective loader DLL sideloaded by a legitimate binary. It uses heavy MBA-based obfuscation, derives a decryption key from the victim machine's volume serial number, decrypts a doubly XOR-encrypted payload, and reflectively loads the final implant.
A 64-bit Windows reflective loader DLL used as the next stage. It uses heavy obfuscation, derives a decryption key from the victim machine's volume serial number, decrypts a final payload protected by layered XOR encryption, and reflectively loads the resulting PE.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.