Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MS17010Test (tests remote Windows systems for EternalBlue vulnerability) ... The port scanner can also invoke the EternalBlue checking code if requested | History and attribution csharp-streamer has been around since at least April 2021... In this post we studied a quite advanced RAT that provides pretty much everything a threat actor requires in preparation of a ransomware attack.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware known as CSHARP-STREAMER is a Remote Access Trojan (RAT) developed in .NET.
History and attribution csharp-streamer has been around since at least April 2021... In this post we studied a quite advanced RAT that provides pretty much everything a threat actor requires in preparation of a ransomware attack.
The malware known as CSHARP-STREAMER is a Remote Access Trojan (RAT) developed in .NET.
The malware known as CSHARP-STREAMER is a Remote Access Trojan (RAT) developed in .NET.
43 distinct techniques documented for this family, organized by ATT&CK tactic.
In our case, the PowerShell script shown initially in this post was downloaded from a server using a small Net.WebClient.DownloadString() snippet in a scheduled task as well as a service in some instances.
In our case, the PowerShell script shown initially in this post was downloaded from a server using a small Net.WebClient.DownloadString() snippet in a scheduled task as well as a service in some instances.
Spawn : Loads a DLL or shellcode into a process; either an existing process, or msiexec.exe is launched as injection target
T1134.001 Access Token Manipulation: Token Impersonation/Theft The malware supports token impersonation.
The scripts we encountered in this case were heavily obfuscated with arithmetic expressions and dead code.
Spawn : Loads a DLL or shellcode into a process; either an existing process, or msiexec.exe is launched as injection target
T1134.001 Access Token Manipulation: Token Impersonation/Theft The malware supports token impersonation.
T1134.002 Access Token Manipulation: Create Process with Token The malware offers the ability to launch processes in different contexts.
The above code base64 decodes a string stored as a byte array and then applies XOR to each character while cycling the key.
[Reflection.Assembly] $assembly = [System.AppDomain]::CurrentDomain.Load($bytes) # Load Assembly
Mimi : Use powerkatz variant of Mimkatz to execute commands logonpasswords/samdump/lsasecrets/lsacache/wdigest/dcsync/passthehash.
Process : List processes, dump process of interest (via pid or name). Probably used to dump the lsass process
Mimi : Use powerkatz variant of Mimkatz to execute commands logonpasswords/samdump/lsasecrets/lsacache/wdigest/dcsync/passthehash.
Keylogger : Turn keylogging on/off. Logs are written to the temp dir with a name of KBDLog-<MM-dd-yyyy>.txt
T1110.001 Brute Force: Password Guessing The malware has an integrated function that supports bruteforcing credentials for smb-access.
T1016 System Network Configuration Discovery The malware enumerates the network configuration of infected hosts.
T1018 Remote System Discovery The malware queries LDAP to discover additional systems.
PortScan : Check an IP address range for a range of open ports to discover interesting applications that may be hosted in the network.
This packet contains some basic information about the machine csharp-streamer is executing on, such as local IP address, domain name, computer name, user name and whether the user is an admin.
T1083 File and Directory Discovery The malware can create filetrees on infected systems.
T1087.001 Account Discovery (Local) The TA uses „ net user “ to enumerate local users on each computer via a Powershell-Script.
T1087.003 Account Discovery (Mail) The TA uses „adsisearcher“ to enumerate mail users on each computer via a Powershell-Script.
T1217 Browser Information Discovery The TA uses NirSoft’s „Browser History View“ [3] to view the History of Internet Explorer, Firefox, Chrome and Safari via a Powershell-Script.
PsExec : Custom psexec-like implementation to copy binaries to a remote system and launch them there as service.
The networking code will attempt to establish a connection to the C2 server via websockets on each of the specified ports, until it succeeds.
Relay : Launch a TCP relay that forwards packets received on a specified port to another system, e.g., an internal host that cannot directly talk to the internet.
T1090.001 Proxy: Internal Proxy The malware has dedicated port-relaying capabilities
-1 has a special meaning and is used if everything else failed - it establishes an ICMP “connection” and camouflages protocol data in ping packets.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular .NET remote access trojan used in multiple intrusions and apparently offered in different feature configurations. Reported capabilities include PowerShell-based in-memory execution, TCP relay/internal proxying, file and directory discovery, keylogging, screenshot capture, LDAP/network discovery, SMB brute forcing, PsExec-style lateral movement, token impersonation, ICMP C2 in some variants, and exfiltration including to Mega.io.
A C# remote access trojan loaded via an obfuscated PowerShell stager that disables AMSI, downloads an XOR/base64-masked .NET assembly disguised as a PNG, loads it in-memory, and connects to a C2 over WebSockets or fallback ICMP. It supports command execution, screenshots, file upload/download, keylogging, credential theft, network scanning, lateral movement, process dumping, payload execution, SMB credential testing, Veeam credential dumping, TCP relay, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.