Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
This design allows the attackers to add capabilities as needed, including command execution...
During post-compromise activity, operators expanded their foothold using legitimate administration software alongside publicly available offensive tools, including Impacket's SecretsDump
including command execution, file manipulation, screenshot capture, clipboard monitoring, keyboard and mouse simulation
These components give the operator command-shell access, file management, keyboard and mouse control, network scanning, credential dumping, keylogging, browser password theft, email collection and remote access. During OctLurk infections, Kaspersky observed the attackers collecting system and network details before deploying tools such as ... a keylogger ...
During post-compromise activity, operators expanded their foothold using legitimate administration software alongside publicly available offensive tools, including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX.
The malware then gathers information about the infected device
SilkLurk was used to open PowerShell, connect to shared network resources with administrative credentials and search for confidential documents. The attackers compressed collected material with WinRAR or 7-Zip, disconnected from network shares to hide which internal servers had been accessed...
Investigators observed SilkLurk searching network shares for sensitive documents
including command execution, file manipulation, screenshot capture, clipboard monitoring, keyboard and mouse simulation
These components give the operator command-shell access, file management, keyboard and mouse control, network scanning, credential dumping, keylogging, browser password theft, email collection and remote access. During OctLurk infections, Kaspersky observed the attackers collecting system and network details before deploying tools such as ... a keylogger ...
These components give the operator command-shell access, file management, keyboard and mouse control, network scanning, credential dumping, keylogging, browser password theft, email collection and remote access. They also installed Pandora remote-control agents and connected directly to email servers using account credentials.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular backdoor that uses DLL sideloading through legitimate NVIDIA and Realtek executables, derives decryption from the victim computer name, persists via Windows services, injects itself into memory, communicates with C2, and executes plugins for espionage, file theft, and broader access operations.
A previously undocumented Windows backdoor used in the same cyber-espionage campaign as OctLurk. It computes a hash from the computer name to unlock its payload path and code, uses legitimate NVIDIA and Realtek programs for DLL side-loading, creates a persistent service, loads its main components into memory, connects to command servers, and can receive plugins enabling command shell access, file management, credential theft, keylogging, browser password theft, email collection, and remote access.
A newly identified malware family in the same espionage framework as OctLurk. It uses DLL side-loading, establishes a TCP connection to its C2 server, collects victim information, receives updated instructions, and loads additional plugins directly into memory to maintain covert access.
An obfuscated backdoor launched through DLL side-loading. It creates a TCP socket to a configured C2 server, collects victim information, executes server-issued commands, adjusts polling intervals, updates configuration, and receives additional plugins for in-memory injection. Post-compromise activity included staging confidential documents and archiving stolen data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.