Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
ipconfig for system network configuration discovery (T1016).
arp -a for both remote system discovery (T1018)... nltest /dclist for the remote discovery of the domain controllers (T1018). ping for network connectivity tests to remote systems (T1018).
Another quite common technique was the inspection of Outlook... On one singular instance, we observed the actor expressing interests in Outlook’s rules.
IcedID itself is composed of multiple modules, one of which is a poorly documented VNC backdoor... acting as a cross-platform remote desktop solution... These backdoors are typically activated during the final initial-access stages to initiate hands-on-keyboard activity.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in an external resource title about VNC backdoors.
Dark Cat is an HDESK VNC backdoor variant used by Qakbot operators. It supports hidden desktop sessions, visible user desktop sessions, alternate start-menu launching of common applications, settings for browser profiles and windows, and likely webcam session support.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.