Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Implant déployé : SecBox (Go), masqué en syscfg.exe (System Configuration Utility).
14 distinct techniques documented for this family, organized by ATT&CK tactic.
ASPX pages invoked Win32_Process.Create through WMI; launchfw.aspx executed the downloaded implant with WMI Win32_Process.Create.
The fake MySQL workflow selected serialized Java objects and included CommonsBeanutils1, CommonsCollections6, and Spring gadget-chain payloads to download a second stage. | The malicious MySQL-compatible service returned crafted data designed to trigger unsafe object processing in a vulnerable Java client, launching a platform-aware downloader on the affected host.
Webshell-launched scripts scanned the internal environment for SMB, WinRM, web, and database services, connecting the public OA system to internal servers and infrastructure.
Webshells used HTTP requests for command execution, SQL and file retrieval, while SecBox supported HTTP task routes including GET /task/{id}, POST /task, and POST /upload.
SecFlow designated authenticated SOCKS5 routes at 43.162.217.10:35888 and 103.45.65.93:35888; the operator retrieved LSASS dump blocks through an authenticated SOCKS route.
SecBox established long-lived C2 connections using TCP, TLS, WebSocket, KCP, or QUIC, with Yamux multiplexing tasking, file transfer, and pivot traffic.
SecBox : implant Go multiprotocole ... Dead Drop Resolver (Pastebin/GitHub Gist, AES-256-GCM).
Les webshells incluent down.aspx et dl_*.aspx ; un fichier c22.exe est référencé via http://158.247.234.124:18000/c22.exe.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Implant Go multiprotocole providing remote access and communications over TCP, TLS, WebSocket, KCP and QUIC. It uses Yamux multiplexing and a Dead Drop Resolver based on Pastebin or GitHub Gist protected with AES-256-GCM.
A Go-based remote-access implant deployed on compromised Windows systems, with related Linux builds. It supports multiprotocol C2 over TCP, TLS, WebSocket, KCP, or QUIC; Yamux multiplexing; remote shell execution; file transfer; download-and-execute; process, token, and service operations; host and port discovery; SOCKS5 proxying; port forwarding; bind pivots; and self-removal. It can use encrypted dead-drop-resolver data from Pastebin or GitHub Gists to rotate C2 infrastructure. No automatic persistence was confirmed in the reviewed builds.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.