Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“Scripts set up cron jobs, systemd timers, rc.local, and OpenRC hooks for persistence.”
“Scripts set up cron jobs, systemd timers, rc.local, and OpenRC hooks for persistence.”
“Scripts set up cron jobs, systemd timers, rc.local, and OpenRC hooks for persistence.”
“Scripts set up cron jobs, systemd timers, rc.local, and OpenRC hooks for persistence.”
“Hermes handles task commands received through Telegram... running commands, and sending back the results.”
Hermes Agent gives the operators a Telegram interface to send tasks to compromised hosts... The agent runs those commands on the victim and returns its report to the Telegram chat.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Docker-targeting botnet that exploits unauthenticated Docker APIs exposed on port 2375 to launch privileged containers, gain host access, establish reverse SSH tunnels, install persistence mechanisms, steal credentials and tokens, execute commands through an AI-agent command loop, and propagate by scanning connected networks for further exposed Docker daemons.
A Docker-targeting worm and botnet implant that compromises unauthenticated Docker daemons exposed on TCP/2375. It launches privileged containers to execute on the host, establishes reverse-SSH access, deploys persistent watchdogs, scans attached networks for further Docker APIs, steals credentials with priority given to AI API keys, and includes a miner disguised as systemd-logind.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.