Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Configuration files and scripts use chained/feedback XOR and a substitution cipher; C2 data is encoded with XOR and Base64.
Trojanized binaries use crond, polkitd, agetty, and atd names, while CentOS functions are named atd_ routines.
The CurlRAT watchdog reads HAProxy PID information and polls /proc to identify started, stopped, restarted, and reloaded states.
Output returns on the raw socket under a standard HTTP/1.0 200 OK header, which is what makes the exchange look like ordinary web traffic.
CurlRAT uses img.monderhouse.space and img.darklights.store as fallback or backup configuration hosts.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Companion Linux remote-access trojan in the ted toolkit. It beacons at a default 12-hour interval, can be configured to beacon every 30 seconds, and only operates when a marker file indicates the infected host is virtualized.
Linux remote-access framework embedded in trojanized system daemons including crond, agetty, atd, and polkitd. It profiles compromised hosts, derives a victim identifier, polls C2 infrastructure over HTTPS with HTTP fallback, executes commands, downloads staged payloads, provides root reverse and interactive PTY shells, and exfiltrates command output and host telemetry. Its HAProxy watchdog reports service state to the operator.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.