Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The commands are encrypted using AES-256-CCM and are delivered as raw bytes, requiring reverse engineering of the custom language.
The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft's dpapi.dll, part of Windows' data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll... The file also has a forged ESET Management Agent version resource
Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory... Five other instructions focus on inbound task reception, such as waiting to receive - or reaching out on its own - a follow-up instruction
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A passive Windows backdoor that impersonates Microsoft's dpapi.dll and side-loads into ESET Management Agent. Rather than beaconing to C2, it monitors network traffic for a magic packet, then decrypts and executes AES-256-CCM-encrypted commands using its own 23-instruction custom language. It supports operations including code execution and data exfiltration, and can also target VMware VMCI.
A previously unseen Windows backdoor hidden in a 64-bit DLL that impersonates dpapi.dll and side-loads via ERAAgent.exe. It remains dormant in memory, passively sniffing for a magic packet, then decrypts and executes a custom 23-instruction bytecode command language. It supports in-memory code execution, staged file delivery, data exfiltration, TCP/UDP and named-pipe communications, and can use VMware VMCI targets instead of normal network addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.