Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
One of the malware families propagated via this method is an updated Windows and macOS version of CountLoader, which comes with new capabilities to establish persistence using scheduled tasks
DeviceManager is equipped to run PowerShell and Python scripts, as well as pipe operator-issued commands into "cmd.exe."
ClickFix commands that, upon execution, search the browser cache for the PNG image and extract from it malicious JavaScript, VBScript, or PowerShell to launch the next-stage component.
DeviceManager, which utilizes EtherHiding to resolve its command-and-control (C2) infrastructure and communicate with the server over HTTP or DNS tunneling.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented modular Python-based RAT distributed via a Delphi-compiled Inno Setup installer. It resolves active C2 nodes through Ethereum/Polygon smart contracts using EtherHiding, avoids CIS-language systems, collects device information, exfiltrates data, polls for tasks, downloads payloads, and executes PowerShell, Python, and cmd.exe commands.
Previously undocumented modular Python-based Windows RAT delivered by DOUBLECUP. It gathers host and domain information outside CIS countries, uses EtherHiding via Ethereum or Polygon smart contracts to resolve C2 infrastructure, and uses DNS A and TXT records for command retrieval, payload download, exfiltration, and command output return.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.