Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution T1059.004 Command and Scripting Interpreter: Unix Shell FontOnLake enables execution of Unix Shell commands.
Execution T1059.006 Command and Scripting Interpreter: Python FontOnLake enables execution of arbitrary Python scripts.
Persistence T1037 Boot or Logon Initialization Scripts FontOnLake creates a system start-up script ati_remote3.modules.
Initial Access T1078 Valid Accounts FontOnLake can collect at least ssh credentials.
Persistence T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions One of FontOnLake’s rootkits can be executed with a start-up script.
Defense Evasion T1014 Rootkit FontOnLake uses rootkits to hide the presence of its processes, files, network connections and drivers.
Defense Evasion T1027 Obfuscated Files or Information FontOnLake packs its executables with UPX.
Initial Access T1078 Valid Accounts FontOnLake can collect at least ssh credentials.
Defense Evasion T1140 Deobfuscate/Decode Files or Information Some backdoors of FontOnLake can decrypt AES-encrypted and serialized communication and base64 decode encrypted C&C address.
Command and Control T1008 Fallback Channels FontOnLake can use dynamic DNS resolution to construct and resolve to a randomly chosen domain. One of its rootkits also listens for specially crafted packets, which instruct it to download and execute additional files. It also both connects to a C&C and accepts connections on all interfaces.
Command and Control T1071.001 Application Layer Protocol: Web Protocols FontOnLake acquires additional C&C servers over HTTP.
Command and Control T1071.002 Application Layer Protocol: File Transfer Protocols FontOnLake can download additional Python files to be executed over FTP.
Command and Control T1095 Non-Application Layer Protocol FontOnLake uses TCP for communication with its C&C.
Command and Control T1132.001 Data Encoding: Standard Encoding FontOnLake uses base64 to encode HTTPS responses.
Command and Control T1568 Dynamic Resolution FontOnLake can use HTTP to download resources that contain an IP address and port number pair to connect to and acquire its C&C. It can use dynamic DNS resolution to construct and resolve to a randomly chosen domain.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.