Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
While the malicious attachments appear to be DOC files due to their file extension, they are actually RTFs crafted to exploit a vulnerability in Microsoft Word: CVE-2012-0158. This particular vulnerability was first exploited in early April 2012 and a patch was released by Microsoft on April 10, 2012. | Attached to the email were what appeared to be three Microsoft Word documents (.doc), but which were trojaned with a malware family we call “Surtr”.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The email in question purported to be from a prominent member of the Tibetan community and repurposed content from a community mailing list. Attached to the email were what appeared to be three Microsoft Word documents (.doc), but which were trojaned with a malware family we call “Surtr”.
It also stores its C2 information and a campaign code in the registry. Depending on the configuration, Surtr will either create multiple registry keys in SoftwareMicrosoftWindows Media in HKU (hkey users) with text data or a single key called XC consisting of binary data.
It also stores its C2 information and a campaign code in the registry. Depending on the configuration, Surtr will either create multiple registry keys in SoftwareMicrosoftWindows Media in HKU (hkey users) with text data or a single key called XC consisting of binary data.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.