SIMPOBOXSPY is a bespoke data-exfiltration malware used by the Earth Kurma APT in espionage intrusions targeting government and telecommunications organizations in Southeast Asia, including reported activity affecting the Philippines, Vietnam, Thailand, and Malaysia. It is specifically described as an exfiltration tool that uploads password-protected WinRAR archives of stolen documents to Dropbox using a specified access token. Earth Kurma used SIMPOBOXSPY alongside ODRIZ, which performed similar exfiltration to OneDrive, to stealthily transfer harvested files such as .pdf, .doc, .docx, .xls, .xlsx, .ppt, and .pptx. In the reported attack chain, documents were collected into a tmp folder, archived with WinRAR, and then uploaded via SIMPOBOXSPY. The malware is part of a broader Earth Kurma toolset that also included TESDAT, DUNLOADER, DMLOADER, Cobalt Strike beacons, the KMLOG keylogger, and the KRNRAT and MORIYA rootkits. Trend Micro noted tooling overlap between SIMPOBOXSPY and activity associated with ToddyCat, but stated attribution remains inconclusive. High-confidence behavior directly described in the source is Dropbox-based exfiltration of archived stolen data via an access token.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...siphon sensitive data using tools like TESDAT and SIMPOBOXSPY... One of the bespoke tools used for data exfiltration is SIMPOBOXSPY, which can upload the RAR archive to Dropbox with a specific access token.
...siphon sensitive data using tools like TESDAT and SIMPOBOXSPY... One of the bespoke tools used for data exfiltration is SIMPOBOXSPY, which can upload the RAR archive to Dropbox with a specific access token.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Component leveraging Dropbox for stealthier data exfiltration.
Tool used for exfiltrating stolen documents to public cloud storage services such as Dropbox and OneDrive.
Custom espionage tool associated with credential theft and data exfiltration; linked in reporting to tooling overlaps with ToddyCat (not conclusive attribution).
Bespoke data-exfiltration malware that uploads staged RAR archives to Dropbox using an access token; noted to share overlaps with tooling associated with ToddyCat (attribution not definitive).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.