Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Significant strings are encrypted... The next stage payload is stored in an encrypted 7z archive... the final stage of PyXie bytecode is contained in an encrypted ZIP file embedded within the interpreter binary... the opcode table had once again been modified.
If it is determined to be running as LocalSystem, the payload is injected into a newly spawned process chosen from the Windows directory. If not found to be running as LocalSystem, the payload will execute in the memory space of the current process.
OpenProcessToken and GetTokenInformation are called to determine if the process is running under the LocalSystem account. This is used to determine how the next stage payload is executed.
_scan_network System Runs network scans... netstat -an ... net view /all ... arp -a ... nslookup -type=any %userdnsdomain%
_main_routine All Collects basic details about the system... As part of the data gathering routines, a number of commands are executed to collect details about the system... systeminfo
_find_files System Searches for and collects files and directories based on keywords, directories and extensions specified in the configuration
net user ... net group "Domain Admins" ... net group "Enterprise Admins" ... net localgroup ... net localgroup "administrators"
PyXie Lite Config ... "shell_cmds": [ ... "net share", "net use", "net view /all /domain", "net view /all" ... ]
OpenProcessToken and GetTokenInformation are called to determine if the process is running under the LocalSystem account. This is used to determine how the next stage payload is executed.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.