Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed an attack on the Royal Road by Vicious Panda in March 2020. It has been reported to execute malware similar to Enfal and BYEBY.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
After the initial connection is established, BYEBY will collect the following system information and upload it to the remote C2: Hostname IP Address
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family referenced as similar to payloads executed by Vicious Panda in Royal Road-related attacks.
BYEBY is a previously unknown DLL backdoor associated with additional CMSTAR samples. It checks whether it is running under svchost.exe or rundll32.exe, can install itself as the 'VideoSrv' service, logs to a temp file, communicates with its C2 over TLS on port 443, uploads host information, and supports commands for authentication, shell access, command execution, drive listing, file transfer, and process execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.