Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The “Command” class. This allows the attacker to interact with the system by issuing shell commands.
The files are then renamed to .bat files and then executed... Malicious VB script is then echoed into another file, “c.txt” in our case. Wscript.exe is then called to execute the newly built file.
The 1.6.0 version’s main Python code was also hidden behind a trivial layer of fernet... This helps attackers reduce the ability for AV detections to trigger on anything malicious as it masked many easily identifiable strings
The not-so-subtle “ KeyRecorder ” class does just as the name suggests — it acts as a keylogger that lets the attacker record the victim’s keystrokes
The configuration parameter IN_NETWORK_SCAN is also new and makes use of the Python class NetworkScanner, which as its name suggests, attempts to probe the surrounding network for IPs and ports.
Other classes allow for general enumeration which provides system information and antivirus protection status.
The not-so-subtle “ KeyRecorder ” class does just as the name suggests — it acts as a keylogger that lets the attacker record the victim’s keystrokes
After analyzing the source code, we can determine that the PY#RATION malware contains the following additional functionalities... Clipboard stealer
The executable “ctask.exe” is then executed... Persistence is established... After executing the 1.0 version of the malware, the attackers downloaded an additional executable, “one.exe”... another Python-based Infostealer malware, which grabs and extracts local PC data including browser credential stores, cryptocurrency wallets, and user and system data.
What makes this malware particularly unique is its utilization of websockets for both command and control (C2) communication and exfiltration... The PY#RATION malware leverages Python’s built in Socket.IO framework
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.