Poison Ivy, also known as PoisonIvy and Darkmoon, is a Windows remote-access trojan used by multiple cyberespionage groups. It provides remote command-line access, system-information theft, keylogging, file transfer, and the ability to download and execute additional payloads. It can discover application window titles and stage collected information locally before transfer. Its communications can be encrypted using the Camellia cipher.
Poison Ivy supports persistence through Registry Run entries, Active Setup, and Windows service creation or modification. Its implant can be generated as shellcode, and it uses shellcode and malicious DLL injection to execute within other processes. Additional evasion behaviors include string obfuscation and deployment of a rootkit. Operators have also used DLL side-loading to load Poison Ivy covertly into memory.
Distribution has included spear-phishing campaigns and watering-hole attacks through compromised legitimate websites. The 2014 th3bug watering-hole campaign deployed Poison Ivy variants against Uyghur sympathizers and organizations in computer manufacturing, higher education, telecommunications, visual computing, and financial services. A 2016 menuPass campaign used Poison Ivy alongside PlugX and ChChes against Japanese academics, pharmaceutical organizations, and a U.S.-based subsidiary of a Japanese manufacturer. Other documented users include Axiom, GALLIUM, Mustang Panda, and Space Pirates. Its use across multiple groups makes the malware alone insufficient for threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“All of the malware were variants of the Poison Ivy Remote Administration Tool (RAT)” used in the watering-hole campaign commonly referred to as “th3bug.”
This RTF file contains malicious code for exploiting CVE-2018-0798 and an object called ‘8.t’. The inclusion of these objects suggests that it was created using the Royal Road RTF Weaponizer. | Previous research on Operation LagTime IT only reported that it used the Royal Road RTF Weaponizer, Poison Ivy and Cotx RAT... The file named 'useless.wll' is Poison Ivy. It is used to download three cab files ('o.cab', 'nbt.cab' and 'in.cab') from the C&C server, and execute the files stored in the cab files.
‘s.exe’ contains an executable file called ‘s.exe’. This is a checker to investigate whether it can be compromised by exploiting MS17-010 against the host passed as an argument... ‘w.exe’ is a tool that actually exploits MS17-010. | Previous research on Operation LagTime IT only reported that it used the Royal Road RTF Weaponizer, Poison Ivy and Cotx RAT... The file named 'useless.wll' is Poison Ivy. It is used to download three cab files ('o.cab', 'nbt.cab' and 'in.cab') from the C&C server, and execute the files stored in the cab files.
[10] Jul 5 CVE-2010-2883 PDF invitation.pdf with Poison Ivy from 112.121.171.94 | pu.flower-show.org | PlugX includes config data like PoisonIvy – e.g., C2 hostname/IP/domain, installed service name/registry value
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Unit 42 observed this new Poison Ivy variant we’ve named SPIVY being deployed via weaponized documents leveraging CVE-2015-2545.
安天2017年针对“绿斑”组织的一个新的前导攻击文档进行了分析,该文档利用最新的CVE-2017-8759漏洞下载恶意代码到目标主机执行。样本采用RTF格式而非之前的宏代码方式,在无须用户交互的情况下就可以直接下载并执行远程文件,攻击效果更好。 | 该WEB服务器上存放了多个不同配置的恶意脚本和可执行文件,一个目录下是一组攻击样本,最终运行的Poison Ivy ShellCode(Poison Ivy是一个远程管理工具)都会连接一个单独C2地址。
另一种是格式攻击文档,利用漏洞CVE-2012-0158来释放并执行可执行文件,同时打开欺骗收件人的“正常”文档文件。... CVE-2012-0158是一个文档格式溢出漏洞... 该组织则使用了MHT格式,这种格式同样可以触发漏洞,而且在当时一段时间内可以躲避多种杀毒软件的查杀。 | 该WEB服务器上存放了多个不同配置的恶意脚本和可执行文件,一个目录下是一组攻击样本,最终运行的Poison Ivy ShellCode(Poison Ivy是一个远程管理工具)都会连接一个单独C2地址。
The spreadsheet contained a zero-day exploit that installs a backdoor through an Adobe Flash vulnerability (CVE-2011-0609). As a side note, by now Adobe has released a patch for the zero-day, so it can no longer be used to inject malware onto patched machines. | In the case of the RSA attack the assault involved a variant of the Poison Ivy Trojan.
The second jar file had a MD5 of 3fbb7321d8610c6e2d990bb25ce34bec and exploited CVE-2013-1493. ... The jar that exploited CVE-2013-1493 dropped a 9002 RAT with a MD5 of 42bd5e7e8f74c15873ff0f4a9ce974cd. ... The exploit site at sunshop[.]com[.]tw previously hosted a different malicious jar file on April 2, 2013. This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT.
China-linked actors using the exploit to deploy POISONIVY, dropped as a BAT file that downloads additional payloads.
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
29 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Red Dev 4 - Background: BlackMould, Poison Ivy, SoftEther VPN, Gh0st RAT, China Chopper
APT10 ceased its use of the Poison Ivy malware family after a security firm comprehensively detailed the malware’s functionality and features.
“The usage of the Camellia cypher in the MSI VFSes, previously seen in APT1-associated Poison Ivy samples is another false flag planted by the attackers.”
Malware used by Mustang Panda Horse Shell, WispRider, PlugX and Poison Ivy, DOPLUGS, MQsTTang, MirrorFace, Sogu
Red Dev 4 - Background: BlackMould, Poison Ivy, SoftEther VPN, Gh0st RAT, China Chopper
29 distinct techniques documented for this family, organized by ATT&CK tactic.
We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer... they compromised several sites, including a well-known Uyghur website written in that native language. | Watering hole attacks offer a much better chance of success because they involve compromising legitimate websites and installing malware intended to compromise website visitors.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
When this file is opened in a vulnerable version of Microsoft Office Word, it will exploit the vulnerability and create a file called ‘useless.wll’ in the Microsoft Word startup directory. | This RTF file contains malicious code for exploiting CVE-2018-0798 and an object called ‘8.t’.
The .wll file located in the Microsoft Office Word startup directory will automatically be loaded and executed when the user starts Word.
The Poison Ivy "useless.wll" placed in the Microsoft Word startup directory is automatically loaded and executed when Microsoft Word is started... test.dll creates the following registry key... HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Master
The attacker used it to inject a DLL file into the compromised host, in the lsass.exe process, to execute it.
The Poison Ivy "useless.wll" placed in the Microsoft Word startup directory is automatically loaded and executed when Microsoft Word is started... test.dll creates the following registry key... HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Master
「主程式被 binary patch 改了一些 call function 以及加上了兩個 sections,一個是 Poison Ivy 的 shellcode」;「使得木馬要加密、變形、免殺變得異常方便」
The attacker used it to inject a DLL file into the compromised host, in the lsass.exe process, to execute it.
If the string exists, it will execute again using rundll32.exe. This time, it will execute a function called ‘DllEntry10’, rather than ‘DllEntryPoint’.
The ‘n.exe’ file that was downloaded and executed by Poison Ivy is a public NBTScan tool. When the tool is executed, it is possible to scan for hosts on the target network.
This is a checker to investigate whether it can be compromised by exploiting MS17-010 against the host passed as an argument. An attacker who finds a laterally deployable host with ‘s.exe’ then uses the ‘w.exe’ contained in ‘w.cab’ to do the actual compromise.
After that, it communicates with the C&C server just like the first Poison Ivy.
It is used to download three cab files (‘o.cab’, ‘nbt.cab’ and ‘in.cab’) from the C&C server, and execute the files stored in the cab files.
221 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
152 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cited as an example of trojans using centralized, HTTP-based command channels that resembled ordinary web traffic but remained vulnerable to domain sinkholing.
Backdoor malware listed in Symantec protections against Elfin attacks.
Mentioned only as a non-exclusive tool that should not be used alone for APT10 attribution.
Shared frameworks such as PoisonIvy, ShadowPad, and more recently NosyDoor, have made attribution through this method increasingly difficult.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.