Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Host-profiling logic collects the computer name, username, operating-system version and architecture, CPU and core count, memory, GPU, disk size, time zone, language, screen details, MAC address, administrator status, antivirus information, and installed-browser details.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware delivered through ClickFix-style social engineering. Victims are presented with a fake Cloudflare CAPTCHA/verification page that induces interaction and leads to malware installation.
A previously unidentified 64-bit Windows information stealer delivered through a ClickFix lure and MSI installer. It collects Chromium-browser credentials and tokens, browser-extension and desktop cryptocurrency-wallet data, profiles the host, creates the psychedelicloveUtils logon scheduled task for persistence, deploys browser-extension/native-messaging components, and communicates with a C2 server for check-ins, stolen-data uploads, and remote task retrieval and execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.