Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Overall, we have observed different obfuscation passes including: Control flow flattening Bogus control flow with common opaque predicates Constant integer encryption Stack-based string obfuscation | Furthermore, Abyssos uses a set of different intermediate representation (IR) passes to obfuscate the binary code.
Dynamically loads any required Windows API functions and libraries. Abyssos iterates the export directory of each loaded library, calculates the CRC32 checksum of the exported function, and compares the result against the expected/passed CRC32 checksum value.
EXECURL_AES_HOL Downloads encrypted shellcode and injects it into a specified process (by name).
SELF_DELETE Abyssos deletes itself using the Windows shell command cmd.exe /C ping 127.0.0.1 -n 3 >nul & del /F /Q file_path .
Checks for the presence of hypervisors. Specifically, Abyssos uses the CPUID instruction to detect the presence of hypervisors, including VMware, KVM, Xen, and VirtualBox. If it detects any of these, Abyssos terminates execution.
KEYLOGGER_GETLOGS Reads the captured keystrokes obtained from the keylogger by reading the hardcoded file windows_update_cache.json
chrome_cdp: Starts the Chrome browser and injects cookies. Specifically, Abyssos creates an instance of Chrome with the debugging port 9222. Then Abyssos connects to it (using the WebSocket protocol) and sets the cookies stored at fontconfigs\cookies.json into the Chrome instance by using Chrome’s API function Network.setCookie . The purpose of this is to hijack browser sessions.
Abyssos ... supports a variety of features including credential theft... RECOVERY Possibly a Chrome credentials harvester module. RECOVERY_GECKO Likely a module that recovers Firefox credentials.
chrome_cdp: Starts the Chrome browser and injects cookies... The purpose of this is to hijack browser sessions.
GRABCOOKIES Likely a module that recovers browser cookies... After executing the module, Abyssos searches and sends any files located at %TEMP%\fontconfigs\ to the C2 server. This command might be combined with the aforementioned network command HVNC_PROG .
PF_START Creates a thread that collects active TCP/UDP connections along with their associated processes every 2 seconds.
Collects host information such as the CPU architecture, computer name, username, user’s integrity level, public IP, and country of origin.
GRABBER_START Creates a thread that scans and collects specified directories/files based on parameters.
DCFINDER Likely a module that scans the network to locate the Domain Controller.
Checks for the presence of hypervisors. Specifically, Abyssos uses the CPUID instruction to detect the presence of hypervisors, including VMware, KVM, Xen, and VirtualBox. If it detects any of these, Abyssos terminates execution.
Initiates a TCP connection with the C2 server... Sends the host’s information to the C2 server along with the binary’s internal version to register the compromised system.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified modular C++ RAT/post-exploitation framework that provides remote administration, credential theft, file exfiltration, VNC-based remote access, process and file management, clipboard interception, keylogging support via modules, shell access, payload download/execution, shellcode injection, UAC bypass, and expandable functionality through additional downloaded modules. It uses AES-GCM for C2 traffic, supports numerous operator commands, and employs obfuscation and some anti-analysis checks.
Abyssos is a Windows remote access trojan/backdoor with anti-analysis checks, encrypted C2 communications, host registration, HVNC capability, remote shell access, file management, process and network monitoring, clipboard interception, screen recording, keylogging support, UAC bypass, payload download/execution, shellcode injection, and modular credential/cookie recovery functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.