Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Alongside the browser framework, the group operates 37 builds of a Rust implant the developers call ClientKing, which reached servers and network devices rather than browsers. It supported five C&C transports, including a custom domain-name-system (DNS) tunnel, and offered a full interactive shell, SOCKS pivoting and the ability to load kernel modules directly from memory.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The APT group performs both functions from a single, custom command-and-control (C2) panel... Whether spying or stealing, Jewelbug group members manage their various infections from a platform called "XG-Web."
One set of implants was configured to utilize the internal proxy of a major U.S. aerospace and industrial manufacturer. | It supported five C&C transports... and offered a full interactive shell, SOCKS pivoting...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based implant for Linux servers, network devices, and routers. It provides an interactive shell, SOCKS pivoting, DNS-tunnel C2 support, and can load kernel modules from memory; a companion toolkit includes a kernel-module rootkit and credential-stealing authentication module.
A custom Linux backdoor used by Jewelbug, primarily in cyber-espionage attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.