Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
CleverSoar employs a persistence mechanism by executing a scheduled task upon user login (T1053).
Subsequently, the installer creates the 'HKCU\SOFTWARE\Magisk' (T1112) registry key
CleverSoar employs a persistence mechanism by executing a scheduled task upon user login (T1053).
If one of these processes is discovered, the installer proceeds to adjust 'Se_Debug_Privilege' ... searches for 'lsass.exe' and writes into that process (T1055).
The installer begins by verifying the existence of the 'C:\cs' folder.It subsequently checks if the process is elevated by executing 'GetTokenInformation' and passing 'TokenElevation' (0x14) as a TokenInformationClass (T1134).
If the process is not elevated, the malware will utilize the 'runas' operation of 'ShellExecuteA' to execute the process with Administrator privileges (T1134.002).
The service will execute an open-sourced Nidhogg rootkit at system startup (T1014).
If one of these processes is discovered, the installer proceeds to adjust 'Se_Debug_Privilege' ... searches for 'lsass.exe' and writes into that process (T1055).
The installer begins by verifying the existence of the 'C:\cs' folder.It subsequently checks if the process is elevated by executing 'GetTokenInformation' and passing 'TokenElevation' (0x14) as a TokenInformationClass (T1134).
If the process is not elevated, the malware will utilize the 'runas' operation of 'ShellExecuteA' to execute the process with Administrator privileges (T1134.002).
Given our high confidence that the malicious files were dropped by a .msi package (T1218.007)
In our instance, the installer checks for 'QEMU' ... presence in the returned buffer (T1497.001).
The created task is concealed by modifying the 'Index' value under 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Corp' registry key to 0 (T1564).
CleverSoar installer enumerates the files present in the folder generated by the malware and modifies their attributes by adding 0x6 (FILE_ATTRIBUTE_HIDDEN + FILE_ATTRIBUTE_SYSTEM). This modification is intended to evade file detection mechanisms (T1564.001).
Subsequently, it enumerates the currently running processes once more (T1057), searching for any instances that contain one of the following strings
Initially, the installer verifies the operating system version by invoking the 'GetVersionExW' function (T1082).
In our instance, the installer checks for 'QEMU' ... presence in the returned buffer (T1497.001).
Next, it enumerates processes and checks if one of 'ZhuDongFangYu.exe', 'QHActiveDefense.exe', 'HipsTray.exe', or 'HipsDaemon.exe' is running (T1518.001).
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.