Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Stage 2: GraftLoader. We track this component as GraftLoader. It is a configurable .NET loader that decrypts an embedded payload, optionally elevates, optionally persists, and then either hollows a host process or loads the payload in process.”
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The registry entry ... is a full PowerShell command line that launches a script the loader drops into the temp directory.
Campaign 1 selects mode 3 and hollows a freshly spawned RegSvcs.exe. Campaigns 2 and 3 both select mode 0 and hollow a new copy of their own process.
Character code reconstruction ... Indirect invocation ... Nondeterministic junk.
Among them sits one bitmap that is not an image at all ... reconstructs a .NET assembly in memory.
It is stored as a byte array inside a named .NET resource in the GraftLoader assembly and decrypted in memory immediately before injection.
Loader filenames imitating system utilities, helper module named after a Windows library.
Campaign 1 selects mode 3 and hollows a freshly spawned RegSvcs.exe. Campaigns 2 and 3 both select mode 0 and hollow a new copy of their own process.
The remaining bytes are decrypted with a keystream ... The final payload ... is decrypted in memory immediately before injection.
The loader builds a setup information file (INF) in the Windows temp directory and launches the installer against it with the auto install switch.
Before it does anything with those arguments, it sleeps ... The sleep value is 19,004 milliseconds.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.