Get2 is a Windows malware family used primarily as a first-stage downloader and loader in financially motivated intrusion campaigns associated with TA505. It has been active since at least 2019 and is commonly delivered through phishing emails carrying malicious Office documents or links to landing pages that serve macro-enabled Excel files. When a victim enables macros, the embedded Get2 component is extracted and executed, after which it performs basic host reconnaissance and contacts command-and-control infrastructure to request follow-on payloads.
Get2 collects system profiling data including the computer name, current username, Windows version, and running processes. Based on server responses, it can retrieve and execute additional malware as either executables or DLLs, including by passing command-line arguments and by injecting DLL payloads into processes. Reporting has linked Get2 to delivery of multiple second-stage families, notably SDBbot, as well as FlawedGrace, FlawedAmmyy, and other TA505-associated tooling. Some variants support selective payload delivery, allowing operators to decide whether a compromised host is of interest before sending later stages.
Get2 has been described both as a downloader and as a loader, and some reporting refers to a backdoor-related component under the name Friendspeak. In observed TA505 operations, Get2 formed part of broader intrusion chains that progressed from phishing-based initial access to installation of remote-access tooling, lateral movement, credential theft, and in some cases enterprise ransomware deployment such as Clop. Targeting has spanned multiple sectors and geographies, including finance, healthcare, government, retail, manufacturing, and other enterprises. The malware’s role is primarily to establish early execution, profile the victim, and stage delivery of more capable payloads while supporting operator-controlled follow-on activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Four hours after the implant was installed, the attackers connected back to the target. One hour later, they used MS17-07 directly against one domain controller to gain AD domain admin rights.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Get2 has the ability to run executables with command-line arguments.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 semble avoir procédé à la distribution de ses charges malveillantes uniquement par campagnes de courriels d’hameçonnage... L’unique vecteur d’infection pour l’instant connu du mode opératoire TA505 demeure le courriel d’hameçonnage incluant une pièce jointe ou un lien malveillant.
These attachments could be zip or 7zip archives containing VBS script or Javascript to be run by their victims, HTML pages containing malicious Javascript, or Offices documents bugged with malicious macros.
L’unique vecteur d’infection pour l’instant connu du mode opératoire TA505 demeure le courriel d’hameçonnage incluant une pièce jointe ou un lien malveillant... ce dernier envoyait directement des liens vers ses pages d’hameçonnage dans ses courriels malveillants.
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
La victime est alors incitée à télécharger, ouvrir et activer les macros VBA d’un document Office, généralement Excel, contenant une charge malveillante.
Ces pièces jointes pouvaient notamment être des archives zip ou 7zip contenant des scripts VBS ou Javascript... Ce dernier redirige la victime vers une URL d’un site légitime mais compromis.
This intrusion set relies exclusively over that period on social engineering to run its payload contained in malicious attachments linked to emails sent... The victim is then encouraged to download, open and enable VBA macros of an Office document.
This code redirects the victim towards an URL of a legitimate but compromised website... The victim is then encouraged to download, open and enable VBA macros of an Office document.
Ce mode opératoire s’appuie exclusivement durant cette période sur de l’ingénierie sociale pour faire exécuter ses charges contenues dans des pièces jointes malveillantes... La victime est alors incitée à télécharger, ouvrir et activer les macros VBA d’un document Office. | Le but de ces documents était souvent d’exécuter via des macros des commandes msiexec sur la machine de la victime pour télécharger et exécuter un code malveillant.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
TA505 has been leveraging the Get2 loader using the same crypter since at least September 2019... the crypter has remained the same with a few modifications every few months.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The decoding is actually done by an encoded blob of bytecode which is decoded in a similar manner to the crypted binary... it will reconstruct the binary data, run the same decoding routine and finally APLib decompress the resulting blob giving us our unpacked Get2 loader.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
127 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TA505-associated loader referenced for similarity to the MSI component used in the MirrorBlast infection chain.
Backdoor capable of identifying the current username of an infected host.
Identifies the current username of an infected host.
Malware capable of DLL injection into processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.