Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the “PYARMOR” string in its main code file “contain.pyc”... is an obfuscating tool for Python script that makes the malware harder to be analyzed and detected.
It usually pretends to be a legitimate file, such as an Adobe PDF or Dropbox file... The attacker also tricks the victim by using an Adobe PDF icon for the decompressed file.
It contains the following modules: ... Clear log ... If not, it uses the following command to delete the data in PSReadline and terminate
It contains Base64-encoded data, which is a PowerShell script.
It also contains environment checking and Anti-VM functions... It then compares the product model to see if it matches any of the following: VirtualBox, VMWare, Hyper-V... It also checks the victim’s hostname against 187 names from VirusTotal machines or other scanner/virtual machines
The second file is “Confirm.zip”. It is a key logger that saves data in the “KeyLogs” folder.
After uploading browser cookies, browser history and cached passwords from Chrome, Firefox and Edge to the “1-Password-Cookies” directory
EvilExtractor also collects system information by PowerShell script, shown in Figure 9.
The stealer also exfiltrates files with mpeg, docx, jpeg, pptx, zip, avi and rar extensions from the victim PC to the “3-Files” directory on the FTP server. The directory structure of the victim’s PC is maintained on the FTP server
It also contains environment checking and Anti-VM functions... It then compares the product model to see if it matches any of the following: VirtualBox, VMWare, Hyper-V... It also checks the victim’s hostname against 187 names from VirusTotal machines or other scanner/virtual machines
The second file is “Confirm.zip”. It is a key logger that saves data in the “KeyLogs” folder.
This stealer collects credentials and files of interest from the victim’s computer and exfiltrates them to an FTP server. It is designed to autonomously collect and exfiltrate data rather than receiving commands from an operator through a command-and-control channel.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer malware that autonomously collects credentials, browser cookies, browser history, cached passwords, system information, Wi-Fi data, and selected files from infected Windows systems, then exfiltrates them to an FTP server. It also downloads additional modules including a keylogger and webcam module.
Windows-focused info stealer delivered via phishing that uses PowerShell and PyInstaller/PyArmor-obfuscated components to steal browser data, passwords, cookies, history, system information, screenshots, selected files, keystrokes, and webcam captures, then uploads the stolen data to an attacker-controlled FTP server. It also includes anti-VM, anti-sandbox, and anti-scanner checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.