Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Initial Access T1566.001 Phishing: Spearphishing Attachment Execution T1204.002 User Execution: Malicious File T1059.001 Command and Scripting Interpreter T1218 System Binary Proxy Execution: ftp.exe Defense Evasion T1027.009 Obfuscated Files or Information
Although it looked like a PDF document, it was actually a Windows shortcut (LNK) file using a PDF icon to appear legitimate.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Initial Access T1566.001 Phishing: Spearphishing Attachment Execution T1204.002 User Execution: Malicious File T1059.001 Command and Scripting Interpreter T1218 System Binary Proxy Execution: ftp.exe Defense Evasion T1027.009 Obfuscated Files or Information T1036.008 Masquerading: Masquerade File Type T1070.004 Indicator Removal: File Deletion
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Go-based backdoor delivered in a multi-stage VHD/LNK infection chain. It performs sandbox evasion, resolves C2 dynamically via Cloudflare Workers, communicates with its C2 over HTTP/3 using QUIC on UDP/443, encrypts C2 traffic with RC4, collects host information, supports shell/file/directory tasking, and persists via a Startup-folder shortcut.
Custom Go-based backdoor delivered via VHD/LNK infection chain. It performs sandbox evasion, resolves C2 through Cloudflare Workers, communicates over HTTP/3 using QUIC with RC4-encrypted traffic, collects host information, supports shell/file transfer/directory listing/heartbeat commands, and persists via a Startup-folder shortcut.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.