Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
또 다른 사례에서는 외부에 노출되어 있던 그룹웨어 시스템의 업로드 페이지를 통해 초기 침투를 시도한 것으로 추정된다. 취약한 파일 업로드 페이지를 이용해 공격자는 웹셸을 업로드했으며 그룹웨어 시스템에 대한 초기 제어권을 확보하였다.
CRAT was first identified in 2020 and was used in various attack cases targeting South Korean users, including spear phishing attacks... The first detected instance of CRAT was distributed via a spear phishing attack using a Hangul document with the file name “Coronavirus Response Emergency Inquiry.Hwp” that exploited the CVE-2017-8291 vulnerability.
“{Random}.Bat” performs its downloader function while simultaneously registering the VBS downloader malware “%PUBLIC%\videos\p{random}.Vbs,” located in the same Path, in the Task Scheduler.
“{random}.bat”은 다운로더 기능을 수행함과 동시에 동일 경로에 위치한 VBS 다운로더 악성코드 “%PUBLIC%\videos\p{random}.vbs”를 작업 스케줄러에 등록한다.
“s{random}.vbs”는 동일 경로에 위치한 BAT 다운로더 악성코드 “%PUBLIC%\videos\{random}.bat”를 실행한다.
As the malware is currently being distributed via LNK files... LNK files are used during the Initial Intrusion phase. The LNK malware acts as a dropper; similar to the security program disguise case described above, it displays a decoy document file while simultaneously creating and executing three script files.
“{Random}.Bat” performs its downloader function while simultaneously registering the VBS downloader malware “%PUBLIC%\videos\p{random}.Vbs,” located in the same Path, in the Task Scheduler.
“{random}.bat”은 다운로더 기능을 수행함과 동시에 동일 경로에 위치한 VBS 다운로더 악성코드 “%PUBLIC%\videos\p{random}.vbs”를 작업 스케줄러에 등록한다.
Once this process is complete, the following command uses RegSvr32 to run XcLoader, which creates and executes a shortcut on the startup path to maintain persistence... Upon execution, it injects itself into a legitimate process and creates a LNK file... and registers an LNK file that executes it via RegSvr32 in the Run key.
“{Random}.Bat” performs its downloader function while simultaneously registering the VBS downloader malware “%PUBLIC%\videos\p{random}.Vbs,” located in the same Path, in the Task Scheduler.
“{random}.bat”은 다운로더 기능을 수행함과 동시에 동일 경로에 위치한 VBS 다운로더 악성코드 “%PUBLIC%\videos\p{random}.vbs”를 작업 스케줄러에 등록한다.
Once this process is complete, the following command uses RegSvr32 to run XcLoader, which creates and executes a shortcut on the startup path to maintain persistence... Upon execution, it injects itself into a legitimate process and creates a LNK file... and registers an LNK file that executes it via RegSvr32 in the Run key.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Xctdoor를 복호화하고 정상 프로세스에 인젝션하는 로더/인젝터 악성코드다. RegSvr32를 통해 실행되며 settings.ini에 지정된 프로세스 또는 explorer.exe에 Xctdoor를 주입한다.
Loader/injector used to decrypt and inject Xctdoor into legitimate processes such as explorer.exe or a process named in settings.ini. It is executed via regsvr32, reads the encrypted Xctdoor payload, decrypts it with XOR, and launches it through process injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.