Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The installer creates four scheduled tasks with schtasks.exe /Create /F /TN ... /XML "%LOCALAPPDATA%\WinDefendSvc\task*.xml".
sys_loader.ps1 and win_conn.ps1 read Base64-encoded diag_pack.dat and win_conn_cfg.dat payload files.
Each PowerShell branch invokes Add-Type, spawning csc.exe and cvtres.exe to compile SSLFix or SSLFix2.
Scheduled tasks use names that imitate Windows components, and files are placed in a folder named "WinDefendSvc," resembling a Windows Defender service.
The payload is staged beneath %LOCALAPPDATA%\WinDefendSvc and uses service-like task names such as Local Credential Manager and Windows Display Manager.
purge.bat runs after payload launch and invokes timeout.exe /T 2 /NOBREAK; the article states its cleanup targets and actual deletion behavior were not observed.
PowerShell assigns the identical historical LastWriteTime of 2024-01-15 08:30:00 to five staged artifacts.
On first run, diag_pack.dat collects local IPv4 information and retrieves public IP, city, country, and ISP details.
Get-WmiObject Win32_Process | Where-Object { $_.CommandLine -like '*sys_loader*' -or $_.CommandLine -like '*win_conn*' }
Documents and archives from all fixed drives are uploaded to the /upload endpoint.
The screenshot command captures the primary display with .NET CopyFromScreen, uploads the PNG, and deletes the temporary file.
On request failure, $SRV_IDX increments and the script rotates between corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows espionage backdoor delivered as a VBScript loader. It establishes persistence through four scheduled tasks and a Startup-folder copy; searches for and exfiltrates business documents; monitors new or changed files; steals saved Wi-Fi passwords and clipboard data; captures screenshots; and executes operator commands. It uses hidden PowerShell modules, mutual watchdog functionality, and a backup command-and-control server.
A persistent, espionage-oriented PowerShell backdoor deployed through a VBS installer. It establishes scheduled-task and Startup-folder persistence, timestomps artifacts, decodes Base64 payloads from DAT files, and uses runtime-compiled C# helpers to bypass TLS certificate validation. It performs automated document theft and continuous file monitoring, exfiltrates data over authenticated HTTPS C2 infrastructure with failover, collects Wi-Fi credentials, clipboard data, screenshots, and host reconnaissance, and executes arbitrary PowerShell commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.