Opachki is a Windows trojan known primarily for link hijacking and web-traffic manipulation. It has been documented as a dropper-delivered threat that installs a DLL payload and uses packing and anti-analysis measures, including Mystic Compressor, on-demand string decryption, and techniques intended to hinder memory dumping and removal. One reported behavior deletes SafeBoot configuration to prevent booting into Safe Mode, reflecting a strong defense-evasion component.
Its core functionality is interception and modification of network traffic in user applications. Opachki hooks network API calls in browsers such as Firefox, Internet Explorer, and Opera, and has also been observed targeting QIP, a Russian ICQ client. It monitors requests and responses and injects malicious script into web content so that links on visited pages are rewritten and users are redirected through attacker-controlled infrastructure. Reporting also indicates logic to serve different script content for traffic originating from search engines, enabling theft or manipulation of search queries and search-result clicks.
Opachki has been characterized as a link-hijacking trojan associated with Google redirections and broader browser-session abuse. It has also shown persistence through startup-related artifacts. Some reporting notes that it checks infected systems for Zeus and renames Zeus-related files, suggesting competition with or takeover of already compromised hosts. The malware has been assessed as likely focused on Russian users, based in part on its targeting of QIP and contemporaneous analysis linking activity to Russia.
Opachki has additionally been observed as one of several malware families capable of downloading and installing FakeRean rogue security software, indicating use as a delivery component in broader criminal malware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
the trojan never actually decrypts all strings in memory but calls a function to decrypt only what it needs and immediately deletes the data after it is not needed. Finally, the packer destroys PE header data from memory to make dumping more difficult.
Both the dropper and the DLL file are packed with a packer called "Mystic Compressor".
Download dropper.exe and dropped rundll32.dll as a password protected archive.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan family observed downloading FakeRean.
A trojan described as a link hijacker that redirects web links/search traffic, including Google redirections. The sample discussed consists of a dropper (dropper.exe) that drops a malicious DLL (rundll32.dll).
A link-hijacking trojan distributed via a dropper that installs a DLL, uses Mystic Compressor packing and on-demand string decryption, destroys PE header data in memory to hinder dumping, deletes the SafeBoot registry key to block Safe Mode, hooks browser and messaging client network APIs, injects malicious script tags into web responses, redirects links/search traffic to attacker-controlled sites, and checks for/removes Zeus infections.
A Win32 trojan dropper identified as Opachki that creates files including %Temp%\nsrbgxod.bak, %UserProfile%\protect.dll, %Programs%Startup\ChkDisk.dll, and %System%\autochk.dll, indicating persistence and payload-dropping behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.