Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The downloaded file is 52,744 bytes and encrypted... The stager decrypts the buffer in place... recovering a Portable Executable.
“The recovered payload is written to the temporary folder under a name resembling a Microsoft Edge component.”
“A position-dependent XOR routine decrypts the data only at runtime, exposing the executable in memory.”
“It also creates a hidden copy and a scheduled task that relaunches it every 30 minutes.”
“Once active, the RAT checks in using the victim’s device identifier and receives tasks from PHP-based server endpoints.”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented .NET Windows remote-access trojan delivered by a stager that profiles the host, downloads an encrypted payload over HTTPS while bypassing certificate validation, and decrypts it at runtime. It establishes scheduled-task persistence, tampers with AMSI, communicates with PHP-based C2 endpoints, and supports live screen streaming, screenshots, command execution via Command Prompt or PowerShell, clipboard monitoring, file download/execution, device control, and runtime DLL plugin loading.
A previously undocumented .NET remote-access tool delivered by an encrypted native stager. It establishes scheduled-task persistence, patches AMSI, registers with and polls a PHP-based C2, captures screenshots and live screen streams, executes shell and PowerShell commands, downloads and runs payloads, monitors the clipboard, controls host power/session state, and downloads runtime DLL plugins.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.