BellaCiao is a Windows malware family written in .NET and associated with the Iranian state-sponsored threat actor Charming Kitten, also known as APT35. Observed in attacks since at least November 2022 and publicly identified in April 2023, it primarily functions as a victim-specific dropper that deploys additional payloads under command-and-control direction. Its principal targets include Microsoft Exchange servers, with activity observed against organizations in the United States, Europe, the Middle East, Turkey, Afghanistan, and India. Individual samples contain hardcoded organization and host information tailored to their intended victims. The initial infection vector has not been established.
BellaCiao attempts to disable Microsoft Defender real-time monitoring and establishes persistence through Windows services masquerading as legitimate Exchange components. It embeds encoded payloads rather than relying exclusively on downloading them. Its distinctive control mechanism uses periodic DNS queries to victim-specific subdomains and interprets returned IP address values as instructions, including whether to deploy or remove webshell artifacts and where to place them.
Payloads include ASPX webshells supporting authenticated command execution and file upload and download. Other variants deploy Plink and a PowerShell web server to establish reverse proxy access and support remote command execution, script execution, and file transfer. These capabilities provide persistent access and covert tunneling into compromised environments; BellaCiao operations have also involved access to RDP servers and credential harvesting. BellaCPP is a C++ reimplementation of the family identified alongside an older .NET BellaCiao implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacker hit-list is described as containing servers compromised using CVE-2021-34473 + CVE-2021-34523 + CVE-2021-31207.
CVE-2021-31207 is named alongside CVE-2021-34473 and CVE-2021-34523 in the ProxyShell chain used against Iranian and Turkish Exchange infrastructure.
Charming Kitten automated exploitation of Microsoft Exchange through the ProxyShell chain: CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. Leaked logs reportedly show nationwide scanning and ASPX webshell deployment. | The article identifies CVE-2021-34473 as a component of the ProxyShell chain used to successfully or partially compromise Exchange servers.
In the next section, we are going to analyze a new implant called BellaCiao, discovered by security researchers from Bitdefender Labs. ... The BellaCiao is a dropper malware – it is designed to deliver other malware payloads onto a victim’s computer system, based on instructions from C2 server.
The exact initial infection vector is unknown, but we expect Microsoft Exchange exploit chain (like ProxyShell/ProxyNotShell/OWASSRF) or similar software vulnerability. Primary target was Microsoft Exchange servers.
The exact initial infection vector is unknown, but we expect Microsoft Exchange exploit chain (like ProxyShell/ProxyNotShell/OWASSRF) or similar software vulnerability. Primary target was Microsoft Exchange servers.
In the next section, we are going to analyze a new implant called BellaCiao, discovered by security researchers from Bitdefender Labs. ... The BellaCiao is a dropper malware – it is designed to deliver other malware payloads onto a victim’s computer system, based on instructions from C2 server.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“These backdoors became live testbeds for Bella Ciao malware variants” and “Episode 2 includes BellaCiao source (dropped as DLLs for DDoS/info-stealing...).”
BellaCPP, a C++ reimplementation of the group's established BellaCiao .NET implant — a webshell-tunneling hybrid first identified in 2023...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The exact initial infection vector is unknown, but we expect Microsoft Exchange exploit chain (like ProxyShell/ProxyNotShell/OWASSRF) or similar software vulnerability. Primary target was Microsoft Exchange servers. | Using automated scanners, vulnerable systems are discovered and automatically compromised (spray-and-pray tactic). Malicious payload (typically a webshell to enable remote administration access) is deployed on compromised server.
The first one was a build of IIS-Raid... looking for pre-defined headers with password and command to execute... The dropped .aspx webshell supports 3 operations: Upload Download Command execution
Upon deployment, BellaCiao immediately attempts to disable Microsoft Defender using the following PowerShell command: powershell.exe -exec bypass -c Set-MpPreference -DisableRealtimeMonitoring $true
These executables run as a service (e.g. “Microsoft Exchange Services Health”).
Decrypt three strings using XOR encryption with the key 0x7B : C:\Windows\System32\D3D12_1core.dll SecurityUpdate CheckDNSRecords Load the DLL file at the path decrypted during the previous step and resolve the functions of the two other decrypted strings above with GetProcAddress.
High-level obfuscation and custom code: Designed to bypass security tools that rely on identifying known malware signatures or behaviors.
Legitimate process names specific to Microsoft Exchange server were used to blend in, a common technique known as masquerading.
Decrypt three strings using XOR encryption with the key 0x7B : C:\Windows\System32\D3D12_1core.dll SecurityUpdate CheckDNSRecords Load the DLL file at the path decrypted during the previous step and resolve the functions of the two other decrypted strings above with GetProcAddress.
To receive instructions from C2 server, BellaCiao is using unique approach of domain name resolution and parsing of the returned IP address. A DNS request is performed every 24 hours to resolve a subdomain...
The PowerShell scripts executes the Plink tool for establishing a reverse proxy connection to the C2 to enable interaction with the PowerShell web server
The second variant drops the Plink tool and PowerShell script hardcoded locations.
The second variant drops the Plink tool and PowerShell script hardcoded locations.
Additionally, it is looking for HTTP requests that include keywords “pass”, “pwd”, “password”, or “login”. Any HTTP request that contains one of these words is appended to the file %LocalAppData%\193d910f01-0293e1a6-591d103f.dat, ready for credential exfiltration.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT35 .NET implant characterized as a webshell-tunneling hybrid.
Malware family referenced in connection with Charming Kitten; a C++ variant (BellaCPP) was observed.
A backdoor used in attacks targeting companies in multiple regions, attributed to Iranian threat actors.
Malware used in Charming Kitten operations for espionage, information theft, and reportedly DDoS activity. The article describes compromised Exchange servers as testing and staging infrastructure, leaked DLL source code, and evolution toward stealthier, modular C++ droppers by June 2025.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.