Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
This design allows the attackers to add capabilities as needed, including command execution...
After establishing the connection, they searched the shared drives for confidential documents to exfiltrate.
including command execution, file manipulation, screenshot capture, clipboard monitoring, keyboard and mouse simulation
including command execution, file manipulation... email collection... The campaign also involved connecting to email servers
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified malware family in the same espionage framework as OctLurk. It uses DLL side-loading, establishes a TCP connection to its C2 server, collects victim information, receives updated instructions, and loads additional plugins directly into memory to maintain covert access.
An obfuscated backdoor launched through DLL side-loading. It creates a TCP socket to a configured C2 server, collects victim information, executes server-issued commands, adjusts polling intervals, updates configuration, and receives additional plugins for in-memory injection. Post-compromise activity included staging confidential documents and archiving stolen data.
A heavily obfuscated backdoor loaded through DLL side-loading of legitimate binaries and decrypted using victim-specific data derived from the computer name. It maintains persistence as a service, connects to configurable C2 hosts directly or through proxies, exchanges encrypted/compressed packets, and supports commands to update configuration and inject additional payloads/plugins into memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.