Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
It will then run a WMI command (wmic process get Caption,ParentProcessId,ProcessId) to get all running processes.
The malware can create a scheduled task called 'OneDriveUpdate' to maintain persistence. The task is configured from an XML file, 'elevator.xml' dropped to APPDATA, to trigger upon logon.
It will then run a WMI command (wmic process get Caption,ParentProcessId,ProcessId) ... To start gathering the information on the victim machine, it will get the OS version using the ver command ... the program will check to see if it is a Windows server by running the command 'systeminfo'
The malware can create a scheduled task called 'OneDriveUpdate' to maintain persistence. The task is configured from an XML file, 'elevator.xml' dropped to APPDATA, to trigger upon logon.
In this option the malware utilizes 'WMIC' to create an event subscription for persistence. Three commands are executed to create events in the 'root\subscription' namespace that will start the payload within 60 seconds of Windows booting up.
The Image File Execution Options key has the following entries set ... This causes the binary for Microsoft Screen Magnifier (magnify.exe) accessibility tool to be backdoored and execute the malware.
The malware can create a scheduled task called 'OneDriveUpdate' to maintain persistence. The task is configured from an XML file, 'elevator.xml' dropped to APPDATA, to trigger upon logon.
In this option the malware utilizes 'WMIC' to create an event subscription for persistence. Three commands are executed to create events in the 'root\subscription' namespace that will start the payload within 60 seconds of Windows booting up.
The Image File Execution Options key has the following entries set ... This causes the binary for Microsoft Screen Magnifier (magnify.exe) accessibility tool to be backdoored and execute the malware.
The following registry entry is created: Key: Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Name: Windows Updater Value: 'C:\Users\AppData\Local\Windows Update\updater10.exe' -1 -0
A GET request is made to https://api.ipify.org to get the public IP address ... Finally, the malware will periodically get information about the local network and adapters.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.