Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
“Some JavaScript is built into the app and can track where a page has been tapped, then replay that as a synthetic touch, click, or scroll. The rest is sent down from the operator’s own servers at runtime, letting them change what the hidden browser does on any page without pushing an app update.”
“BootNova also takes steps to keep its own communication out of sight. A module the researchers labeled RsaUtils decodes the hardcoded C2 address, along with the messages exchanged with the server, using Base64 and a character-shifting cipher, so the address doesn’t sit in plain text for anyone inspecting the app.”
“Papyrus is built around BootNova, an orchestration layer that controls hidden browser activity inside the app. When the app runs, BootNova contacts remote command-and-control infrastructure for configuration. The C2 can determine whether the hidden activity should run, where it should run, which URLs should be loaded, how many webviews should be active, and how those webviews should interact with loaded pages,”
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.