Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"{Random}.Bat" downloads XcLoader and Xctdoor... "Settings.Lock," which is loaded into and executed by the RegSvr32 process via a LNK file, is an injector malware.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
In another case, it is presumed that the threat actor attempted an Initial Breach through the upload page of a groupware system that was exposed to the outside. By exploiting a vulnerable file upload page, the threat actor uploaded a web shell...
CRAT was first identified in 2020 and was used in various attack cases targeting South Korean users, including spear phishing attacks... The first detected instance of CRAT was distributed via a spear phishing attack using a Hangul document with the file name “Coronavirus Response Emergency Inquiry.Hwp” that exploited the CVE-2017-8291 vulnerability.
“{Random}.Bat” performs its downloader function while simultaneously registering the VBS downloader malware “%PUBLIC%\videos\p{random}.Vbs,” located in the same Path, in the Task Scheduler.
“p{random}.Vbs” downloads the PowerShell script “%PUBLIC%\videos\2.Ps1”. The PowerShell script “%PUBLIC%\videos\2.Ps1” moves the file that was downloaded with the random name... It also XOR-decodes the “l{random}” file...
“S{random}.Vbs” executes the BAT downloader malware “%PUBLIC%\videos\{random}.Bat,” located in the same Path... 0X10021 Multiple command execution (using cmd /c)
First, the VBS launcher malware “%PUBLIC%\videos\s{random}.Vbs” is executed. “S{random}.Vbs” executes the BAT downloader malware... while simultaneously registering the VBS downloader malware “%PUBLIC%\videos\p{random}.Vbs”
As the malware is currently being distributed via LNK files... LNK files are used during the Initial Intrusion phase. The LNK malware acts as a dropper; similar to the security program disguise case described above, it displays a decoy document file while simultaneously creating and executing three script files.
“{Random}.Bat” performs its downloader function while simultaneously registering the VBS downloader malware “%PUBLIC%\videos\p{random}.Vbs,” located in the same Path, in the Task Scheduler.
In one case, the threat actors first compromised an unmanaged Windows IIS web server to install a web shell... By exploiting a vulnerable file upload page, the threat actor uploaded a web shell and gained initial control over the groupware system.
Once this process is complete, the following command uses RegSvr32 to run XcLoader, which creates and executes a shortcut on the startup path to maintain persistence... Upon execution, it injects itself into a legitimate process and creates a LNK file... and registers an LNK file that executes it via RegSvr32 in the Run key.
“{Random}.Bat” performs its downloader function while simultaneously registering the VBS downloader malware “%PUBLIC%\videos\p{random}.Vbs,” located in the same Path, in the Task Scheduler.
In the 2024 incident, the threat actor also used XcLoader to inject Xctdoor into legitimate processes... If the “settings.Ini” file exists, the process name stored as a string in that file is retrieved, and the previously decoded roaming.Dat PE file is injected into that process.
Once this process is complete, the following command uses RegSvr32 to run XcLoader, which creates and executes a shortcut on the startup path to maintain persistence... Upon execution, it injects itself into a legitimate process and creates a LNK file... and registers an LNK file that executes it via RegSvr32 in the Run key.
In the 2024 incident, the threat actor also used XcLoader to inject Xctdoor into legitimate processes... If the “settings.Ini” file exists, the process name stored as a string in that file is retrieved, and the previously decoded roaming.Dat PE file is injected into that process.
Execution command: C:\WINDOWS\system32\regsvr32.Exe /s %LOCALAPPDATA%\Packages\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\Settings\settings.Lock... the threat actor exploited a Korean ERP solution by inserting a routine into the module responsible for updates that used the Regsvr32.Exe process to execute a malicious DLL.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.