Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PSNATCH is a new PowerShell-based file-stealing tool that scans a pre-configured list of directories and exfiltrates files matching a pre-configured list of extensions to the threat actor’s private GitHub repositories.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell file stealer that recursively collects recently modified files from user folders and local drives, limits collection by file and total size, tracks previously uploaded files for incremental theft, and exfiltrates data through private GitHub repositories using a hardcoded personal access token.
A PowerShell file stealer that recursively collects recently modified files from user directories and drives, tracks previously uploaded files for incremental collection, and exfiltrates data to per-victim private GitHub repositories via the Contents API.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.