Symmi, also referred to as MewsSpy and Graftor, is a Windows malware family notable for its domain generation algorithm used for command-and-control discovery. Samples documented from late 2014 through early 2015 used a configurable DGA whose parameters were stored as XOR-obfuscated strings. The algorithm seeded an inlined msvcrt-style pseudo-random number generator from the current date and a hardcoded constant, rotated domain sets on a 16-day cycle, and generated 64 candidate domains per cycle under a dynamic DNS suffix. The generated labels alternated vowels and consonants to produce somewhat pronounceable names, and implementation flaws excluded some characters from ever being selected.
Observed behavior shows Symmi aggressively attempting DNS resolution of many generated domains in rapid succession. When all generated domains resolve to NXDOMAIN, the malware waits briefly and restarts the process; when a command-and-control site is unreachable for other reasons, it waits longer before retrying. This behavior indicates automated command-and-control rendezvous through DGA-generated infrastructure and supports classification as a backdoor-oriented malware family with reconnaissance-like network discovery of active control nodes.
Symmi has also appeared in infrastructure clustering alongside other criminal malware operations, including domains associated with Bedep, Kazy, and the Chir mail worm. High-confidence reporting links some of this surrounding infrastructure to activity connected with the Angler exploit kit ecosystem, although direct attribution of Symmi itself to a specific threat actor is not established from the available facts. The available evidence supports Symmi as a Windows malware family using DGA-based command-and-control discovery, but does not support stronger conclusions about payload objectives such as credential theft or data exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
96 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another threat linked through shared registrant/domain artifacts.
A malware family analyzed for its domain generation algorithm (DGA). It rapidly attempts DNS resolution of many generated domains, using a date-based seed plus a configurable constant to generate pronounceable third-level domains under .ddns.net, cycling through up to 64 domains before sleeping and retrying for C2 communication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.