Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
| Tactics | Techniques | ... | Lateral Movement | T1021 : Remote Services - nT1078 : Valid Accounts - nT1570 : Lateral Tool Transfer |
| Tactics | Techniques | ... | Initial Access | T1566 : Phishing - nT1190 : Exploit Public - Facing Application - nT1199 : Trusted Relationship |
루트 권한이 아니라면 아래 과정을 거쳐 크론탭 방식으로 지속성을 확보한다. crontab -l 로 기존 내용을 읽고, */10 * * * * <자기 경로> 항목을 붙여 cron.txt 에 기록
If the first byte of the server response is S (0x53), the remainder is decoded as URL-safe Base64... The first 4 bytes of the decoded result serve as the decryption key... DriveTroy ... configuration data is RC4-encrypted and then encoded with the URL-safe Base64
/var/log/rsyslogd 로 자기 복사 ... /etc/systemd/system/rsyslogd.service 유닛 작성 ... DriveTroy ... 서비스명 | syslogd , logd , cachelogd , cachemond , monlogd 중 랜덤 선택
원본 삭제 ... crontab cron.txt 실행 cron.txt 삭제 후 재실행 ... delete | Bird_module_shell . Selfdelete | 자가 삭제 ... 06 | Die | 자가 삭제 + 종료
After initializing the Engine, it sends an HTTP GET request to hxxps://api[.]ipify[.]org and looks up the victim system's external IP address.
Gomir는 C&C 서버와의 메인 통신 루프에서 HTTPS POST 방식을 사용하며 ... BirdTroy는 ... HTTP POST 방식으로 전송하며 ... DriveTroy는 구글 드라이브의 E8C46207.cmd 파일을 1초 간격으로 다운로드하여 명령을 수신한다.
DriveTroy is a backdoor that abuses Google Drive as its C&C server ... uploads it to Google Drive under the filename E8C46207.ses ... polls commands by downloading the E8C46207.cmd file from Google Drive every second ... uploads it ... under the filename E8C46207.res
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based Linux backdoor and apparent Gomir variant that abuses Google Drive for C2. It extracts embedded configuration, uses RC4 plus URL-safe Base64 for communications, polls Google Drive for commands, uploads results, supports shell execution, file transfer, persistence, self-deletion, and connection testing.
Go-based Linux backdoor assessed as a newly developed Gomir variant. It stores encrypted configuration in its own file, uses Google Drive for command polling and result upload, gathers system and external IP information, executes shell commands, transfers files, establishes persistence, and can self-delete.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.