Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
In the crontab, but only if at least one CRON job already exists. The inserted entry relaunches the program every five minutes.
In the user’s systemd configuration, specifically ~/.config/systemd/user/systemd-journal-helper-service
In the crontab, but only if at least one CRON job already exists. The inserted entry relaunches the program every five minutes.
In the user’s systemd configuration, specifically ~/.config/systemd/user/systemd-journal-helper-service
The malware then copies itself to ~/.config/systemd-runtime/systemd-journald-helper, which becomes the binary used for subsequent executions.
When executed, the malware uses numerous methods to determine whether its execution context is being monitored. These include: CPUINFO, to determine whether it is running on a virtual CPU ... Reading /proc/modules to look for hv_vmbus, vmw_vmci ... Checking the MAC address in use, particularly whether it starts with a VM-related prefix
It collects: The current user, including contextual information such as their shell and whether they are root
It collects: ... The available network interfaces ... Interesting installed packages, such as SSH, VNC, Apache, Docker, and so on
It collects: The hostname ... The machine configuration, including the operating system, architecture, kernel, RAM, and so on
When executed, the malware uses numerous methods to determine whether its execution context is being monitored. These include: CPUINFO, to determine whether it is running on a virtual CPU ... Reading /proc/modules to look for hv_vmbus, vmw_vmci ... Checking the MAC address in use, particularly whether it starts with a VM-related prefix
Two keylogging methods are implemented ... If the device is accessible, it simply reads the input events ... Otherwise, it falls back to X11 ... !keylog start/stop/dump Manages the keylogging thread
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.