Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The agents actively searched server-side systems, identified weaknesses, and carried out targeted actions against online infrastructure... [The Recon] dashboard was designed to organize, validate, and manage more than 23,800 stolen secrets in real time, including API keys connected to cloud and AI services.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-agent, post-compromise credential-harvesting framework operated from a compromised cloud environment. It used agent configuration and knowledge files to automate vulnerability scanning, credential collection, troubleshooting, and IP rotation, then managed harvested secrets through a dashboard.
An autonomous multi-agent post-compromise framework used to scan for weaknesses, collect and validate credentials and API keys, troubleshoot errors, and rotate internet-facing IP addresses. Its exposed C2 dashboard managed more than 23,800 harvested secrets.
An automated reconnaissance and credential-management framework hosted on an exposed C2 server. It organizes, validates, and manages stolen secrets, including cloud and AI-service API keys, in real time.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.