The NSA and FBI published a joint advisory describing Drovorub, a malware platform attributed to Russia’s GRU GTsSS, military unit 26265, and detailing its command-and-control behavior, including WebSocket-based communications. Building on those indicators and protocol details, Insane Forensics released an open-source hunting tool designed to help defenders identify Drovorub activity across both historical PCAP data and live network traffic using Elasticsearch, Kibana, Python, and TShark, with pivots for sessions, modules, actions, tunnels, and file transfers.
Separate malware analysis by FortiGuard Labs showed a memory-resident Windows payload launched inside dllhost.exe after script- and PowerShell-based execution, with corrupted PE headers that required manual reconstruction from memory. The sample decrypted the C2 domain rushpapers.com on port 443, used a WebSocket-style HTTP upgrade over TLS, and added a custom XOR-based encryption layer, while exposing remote-access functions such as screenshot capture, active-window collection, service control, and listener mode. Together, the reporting highlights how defenders are tracking malware families that hide C2 traffic inside WebSocket-like channels and how network-focused hunting can help surface that activity.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Incident Response reported analysis of a memory-resident Windows malware sample recovered from a compromised machine, reconstructing the payload from memory after its PE headers were corrupted. The analysis found the malware used TLS plus a WebSocket-style HTTP upgrade to communicate with rushpapers.com on port 443 and confirmed RAT capabilities including screenshots and listener mode.
Insane Forensics released a free, open-source tool to hunt for Drovorub command-and-control traffic using Elasticsearch, Kibana, Python, and TShark. The tool was built from technical indicators and protocol details in the NSA/FBI report rather than real malware samples or packet captures.
The NSA and FBI released a report describing the command-and-control capabilities of Drovorub malware and attributed it to Russia’s GRU 85th Main Special Service Center (GTsSS), military unit 26265.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourcegithub.com
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.