Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
| Tactics | Techniques | ... | Lateral Movement | T1021 : Remote Services - nT1078 : Valid Accounts - nT1570 : Lateral Tool Transfer |
| Tactics | Techniques | ... | Initial Access | T1566 : Phishing - nT1190 : Exploit Public - Facing Application - nT1199 : Trusted Relationship |
루트 권한이 아니라면 아래 과정을 거쳐 크론탭 방식으로 지속성을 확보한다. crontab -l 로 기존 내용을 읽고, */10 * * * * <자기 경로> 항목을 붙여 cron.txt 에 기록
If the first byte of the server response is S (0x53), the remainder is decoded as URL-safe Base64... The first 4 bytes of the decoded result serve as the decryption key... DriveTroy ... configuration data is RC4-encrypted and then encoded with the URL-safe Base64
/var/log/rsyslogd 로 자기 복사 ... /etc/systemd/system/rsyslogd.service 유닛 작성 ... DriveTroy ... 서비스명 | syslogd , logd , cachelogd , cachemond , monlogd 중 랜덤 선택
31 | Process_Download | Transfer a file from the victim system to the C & C server ... DriveTroy ... 03 | UploadFile | Upload a file from the victim's PC to Google Drive
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unpublished Go-based Linux RAT/backdoor that combines traits of Gomir and HttpTroy. It supports persistence identical to Gomir, HTTP or HTTP/3 C2 communications, shell execution, self-deletion, screenshot capture, and bidirectional file transfer.
Previously undocumented Go-based Linux RAT/backdoor that appears to be a Gomir variant. It supports persistence, duplicate-execution prevention, HTTP or HTTP/3 C2 transport, shell command execution, screenshot capture, self-deletion, sleep control, and bidirectional file transfer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.