DiagTrack.exe is Windows malware associated with Chinese government-linked intrusion activity enabled by Integrity Technology Group. It masquerades as legitimate Windows software and establishes encrypted communications over HTTP with infrastructure attributed to Integrity Technology Group. The malware contains mailbox-querying functions.
Its delivery chain uses JavaScript and HTML cross-site scripting payloads to modify vulnerable webpages and display credential-harvesting fields. After credentials are submitted, the modified page offers a password-protected ZIP archive containing an executable that launches the malware.
The associated intrusion activity overlaps with activity tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, without establishing that these attribution groupings are equivalent. These broader campaigns target U.S. critical infrastructure and organizations across Southeast Asia, Africa, and North America, including government, healthcare, manufacturing, information technology, law enforcement, education, and religious organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The executable starts a process named DiagTrack.exe, which uses the same name as legitimate Windows software. The process establishes encrypted communications over HTTP with dns.studiocloud[.]xyz.
The executable starts a process named DiagTrack.exe, which uses the same name as legitimate Windows software. The process establishes encrypted communications over HTTP with dns.studiocloud[.]xyz.
“DiagTrack.exe then establishes encrypted communications over the HTTP protocol with the domain dns.studiocloud.xyz, which the FBI attributes to Integrity Tech.”
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malicious executable delivered through credential-harvesting pages during initial access. Its additional capabilities are not described.
Malicious process launched by live700_v1.exe, delivered in a password-protected ZIP archive through an XSS credential-harvesting page. It impersonates legitimate Windows software and communicates with attacker infrastructure. Mailbox-querying functions suggest email-theft capabilities.
Malicious component launched by live700_v1.exe that masquerades as legitimate Windows software. It establishes encrypted HTTP communications with attacker infrastructure and contains functions for querying user mailboxes, supporting the FBI's assessment of likely email exfiltration. This entry refers only to the malicious sample, not legitimate Windows software with the same name.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.