hamzazaheer is the name associated with a 2024 NuGet supply-chain campaign targeting ASP.NET developers through malicious packages published to the .NET package ecosystem. The activity involved multiple packages masquerading as legitimate development components, including a typosquatted cryptography-themed package and companion libraries that integrated into ASP.NET Identity and application service registration flows. The apparent objective was to compromise developer builds and introduce persistent backdoor functionality into deployed web applications. The campaign used a staged architecture. One package functioned as an obfuscated stage-1 dropper that executed on assembly load, installed runtime hooks to decrypt hidden code, and deployed a second-stage component. That second stage established a localhost proxy used by the companion packages as an internal relay to attacker-controlled command-and-control infrastructure resolved dynamically at runtime. Additional packages exfiltrated ASP.NET Identity authorization data, including user, role, and permission relationships, and accepted attacker-controlled authorization responses that could modify role and user permissions inside victim applications. Another package provided file-write and hidden process-execution functionality consistent with post-compromise payload staging and execution. Observed tradecraft includes typosquatting, execution on load, heavy obfuscation, runtime/JIT manipulation, covert local proxying, exfiltration of authorization data, and abuse of dependency injection patterns to blend malicious logic into normal ASP.NET application behavior. Shared embedded credentials, common build artifacts, and metadata similarities across the packages indicate common authorship and coordinated operation. The activity is best characterized as a software supply-chain intrusion focused on unauthorized access and persistence within downstream web applications rather than ransomware or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.