Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The script uses Schedule.Service to register a logon task named '\MicrosoftEdgeUpdateTaskCore'.
conhost.exe was intended to launch PowerShell with '-NoP -NonI -W Hidden -EncodedCommand'.
The downloader parses the PNG iTXt chunk, locates marker 'FF 89 AD 4A', then XOR-decrypts and DEFLATE-decompresses the recovered data.
The PowerShell loader reconstructs a .NET executable, and the first .NET loader contains an embedded encrypted executable.
The chain uses an encoded PowerShell command, Base64 payload fragments, AES-128-CBC, and RC4.
The PowerShell stage decompresses data using GZipStream, while the PNG-derived payload is decompressed using DEFLATE.
The JavaScript contains 450 comment lines with seemingly random English words and substantial nonfunctional bulk.
[The message] appeared to impersonate an employee of a legitimate company.
The registered persistence task is named '\MicrosoftEdgeUpdateTaskCore'.
For a recovered native executable, the loader selects a process-hollowing routine; managed assemblies are instead loaded through reflection.
The PowerShell code calls 'Remove-Item $Laswgh , $rLkHQC -Force' after reading the two temporary payload-fragment files.
The PowerShell script combines files, Base64-decodes them, AES-decrypts the result, and decompresses it; the .NET loader performs RC4 decryption.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage loader delivered through a malspam attachment. It uses heavily padded/obfuscated JavaScript, process-environment variables and temporary files to hand off payload fragments to PowerShell, AES/GZip decoding, in-memory .NET assembly loading, scheduled-task persistence, AMSI-patching attempts, RC4-protected secondary loading, and a PNG iTXt-chunk payload retrieval mechanism. The ultimate downloaded payload family was not determined.
A malware loader discussed in an analysis focused on passing data between its stages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.