Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CornFlake is a full-featured Windows RAT written in Go that serves as Storm-2945’s primary persistent implant.
CornFlake is a full-featured Windows RAT written in Go that serves as Storm-2945’s primary persistent implant.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
ChocoShell is the campaign’s Powershell-based infostealer, delivered and executed entirely in-memory.
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
Collects 18 categories of host intelligence including installed software, antivirus (AV)/endpoint detection and response (EDR) products, Defender exclusions, User Account Control (UAC) level
ChocoShell communicates with its C2 server using HTTPS with URI paths designed to blend in with legitimate web traffic.
ChocoShell communicates with its C2 server using HTTPS with URI paths designed to blend in with legitimate web traffic.
active traffic manipulation attacks leading to the delivery of malware on impacted systems
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based Windows remote access trojan used as Storm-2945’s primary persistent implant. It operates in dropper mode, establishes persistence via services, Run keys, scheduled tasks, and a watchdog, and supports keylogging, clipboard capture, screenshots, audio/video surveillance, browser credential theft, file exfiltration, USB monitoring, security posture collection, and remote shell access over an encrypted C2 channel.
A Go-based Windows remote access trojan used as Storm-2945’s primary persistent implant. It copies itself to %APPDATA%\svchost32\svchost32.exe, establishes persistence via services, Run keys, scheduled tasks, and a watchdog, and provides capabilities including keylogging, clipboard capture, screenshots, audio/video surveillance, browser credential and cookie theft, file exfiltration, USB monitoring, host reconnaissance, and remote shell access over an encrypted custom C2 channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.