Pacifier is a cyber-espionage malware toolkit and campaign active from 2014 through at least May 2016, primarily targeting Romanian institutions, with related detections in Iran, India, the Philippines, Russia, Lithuania, Thailand, Vietnam, and Hungary. The activity cluster is known as Pacifier APT. It targeted Windows systems through spear-phishing emails carrying malicious Microsoft Word documents that required macro enablement, and later through ZIP archives containing double-extension JavaScript droppers. Lures included résumés, invitations, conference material, official instructions, and urgent notices.
Pacifier used staged droppers to install modular backdoors, establish persistence through autorun mechanisms, altered shortcuts, and scheduled tasks, and inject backdoor components into legitimate browser, email-client, and Windows processes. Its later variants reduced process-list visibility by operating through injected legitimate processes. Backdoor functionality included remote command execution, file upload and download, file deletion, directory enumeration, configurable beacon timing, and self-removal. Command-and-control traffic used HTTP or HTTPS, including encrypted or encoded communications; some variants bypassed certificate-validation errors. A branch of the toolkit deployed a malicious Firefox extension masquerading as a language pack and provided comparable command execution, file-transfer, and directory-listing capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pacifier is a cyber-espionage malware set used in spear-phishing campaigns against Romanian institutions and foreign targets. It evolved from macro-delivered droppers and executable backdoors into stealthier injected components and a Firefox extension backdoor. Its capabilities include persistence, process injection into browsers and Outlook, C2 communications over HTTP/HTTPS, remote command execution, file upload/download, directory listing, self-deletion, and scheduled-task/registry-based persistence.
Pacifier is a cyber-espionage malware set used in spear-phishing campaigns against Romanian institutions and foreign targets. It evolved from macro-delivered droppers and executable backdoors into stealthier injected components and a Firefox extension backdoor. Its capabilities include persistence, process injection into browsers and Outlook, C2 communications over HTTP/HTTPS, remote command execution, file upload/download, directory listing, self-deletion, and scheduled-task/registry-based persistence.
Pacifier is a cyber-espionage malware set used in spear-phishing campaigns against Romanian institutions and foreign targets. It evolved from macro-delivered droppers and executable backdoors into stealthier injected components and a Firefox extension backdoor. Its capabilities include persistence, process injection into browsers and Outlook, C2 communications over HTTP/HTTPS, remote command execution, file upload/download, directory listing, self-deletion, and scheduled-task/registry-based persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.