Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
It drops Windows Script Host’s CScript component... One fake Adobe Acrobat variant used wscript.exe rather than cscript.exe, suggesting the operators can adjust the loader while keeping the broader delivery chain intact.
The background component can collect browser cookies, capture the active tab, maintain a local relay, and inject attacker-provided JavaScript into an open page.
GhostDesk records entries typed into form fields and looks for submitted data tied to credentials, authentication tokens, and financial information.
Form-based credential harvesting: The script listens for outgoing POST requests and submit events, acting as a man-in-the-middle to capture submitted data.
Cookie theft: The script uses chrome.cookies.getAll to grab the user’s browser cookies and send them to the WebSocket relay.
GhostDesk records entries typed into form fields and looks for submitted data tied to credentials, authentication tokens, and financial information.
Form-based credential harvesting: The script listens for outgoing POST requests and submit events, acting as a man-in-the-middle to capture submitted data.
The background component can collect browser cookies, capture the active tab, maintain a local relay, and inject attacker-provided JavaScript into an open page.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Browser spyware delivered via fake software installers that modifies Chrome extension loading to gain persistent browser access. It captures keystrokes and form data, steals credentials, cookies, authentication tokens and financial information, takes screenshots/captures active tabs, injects attacker-supplied JavaScript into pages, maintains a local relay/WebSocket channel, and can replace pasted cryptocurrency addresses.
Browser-based spyware delivered via fake software installers. It patches Chrome’s Security Extension, installs malicious extension components, establishes C2 communications, and steals credentials, cookies, screenshots, and keystrokes while also enabling script injection and arbitrary JavaScript execution in the active tab.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.