Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ChocoShell is the campaign’s Powershell-based infostealer, delivered and executed entirely in-memory.
ChocoShell is the campaign’s Powershell-based infostealer, delivered and executed entirely in-memory.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks
the malware obtains by impersonating a SYSTEM process token borrowed from winlogon.exe, wininit.exe, or services.exe
SilentCleanup task hijack: Writes a malicious command to HKCU\Environment\windir , then triggers the built-in SilentCleanup scheduled task
wsreset.exe COM hijack: Creates a COM handler key in HKCU\Software\Classes and launches the auto-elevating Windows Store reset tool.
Locked browser SQLite databases are accessed through three strategies: shared file access, Volume Shadow Service snapshots
After exfiltration... VSS shadow copies are deleted via Windows Management Instrumentation (WMI), temporary elevation scripts are removed
the malware obtains by impersonating a SYSTEM process token borrowed from winlogon.exe, wininit.exe, or services.exe
ChocoShell communicates with its C2 server using HTTPS with URI paths designed to blend in with legitimate web traffic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An in-memory PowerShell infostealer focused on stealing browser cookies, saved passwords, Microsoft 365 SSO tokens, Azure AD/WAM tokens, and Wi-Fi credentials. It disables AMSI, uses sandbox checks, communicates with a hardcoded HTTPS C2, performs UAC bypass and SYSTEM token impersonation, abuses Chrome remote debugging for cookie extraction, and cleans up artifacts after exfiltration.
An in-memory PowerShell infostealer focused on stealing browser session cookies, saved passwords, Microsoft 365 SSO tokens, Azure AD/Web Account Manager tokens, and Wi-Fi credentials. It disables AMSI, uses HTTPS paths masquerading as benign web traffic for C2, employs multiple UAC bypass techniques for elevation, abuses SYSTEM token impersonation and browser remote debugging to bypass Chrome App-Bound Encryption, and exfiltrates collected data as compressed Base64-wrapped JSON.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.