Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
In most cases where we have been able to identify the droppers, the attack begins with an executable file being sent directly to targets via e-mail. Occasionally the attackers leverage builders for known document exploits, but most of the time they still use self-extracting binaries. The themes of the phishing e-mails vary according to the target...
both using Yahoo Answers and Quora to evade traditional mechanisms for blocking command and control domains
The malware requests the page shown below in order to determine what IP to POST to... Figure 4 – HTTP POST request made to command and control server
cyber espionage threat actors are increasingly abusing legitimate web services, in lieu of DNS lookups to retrieve a command and control address... more recent samples of the CONFUCIUS_A malware use a range of legitimate web services to resolve command and control addresses, the highest profile of which are Yahoo and Quora.
132 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware family linked to attacks focused largely on Pakistan and other targets in the Middle East and Asia. Later variants resolve command-and-control addresses by retrieving content from legitimate web services such as Yahoo and Quora and decoding keywords into an IP address before POSTing to the C2.
Backdoor malware family used in espionage-oriented attacks. Early samples did not use legitimate web services for DNS resolution, but later samples used services such as Yahoo and Quora to derive command-and-control IP addresses from page content via a lookup table, then POST to the decoded C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.