Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareUsed by 1 actor

Screenshotter

Screenshotter is a malware family and utility used to capture periodic screenshots from infected Windows systems and exfiltrate them to attacker-controlled command-and-control infrastructure over HTTP, typically via POST requests. Reporting ties it closely to TA866, also known as Asylum Ambuscade, which used it in financially motivated intrusion chains and possibly espionage-related activity. In observed TA866 campaigns, initial access commonly came via malspam, malvertising, or 404 TDS redirection to malicious JavaScript downloaders, which retrieved MSI packages. A WasabiSeed downloader then established persistence via an LNK shortcut in the Windows Startup directory, polled C2 using the victim drive serial number, and downloaded Screenshotter as a follow-on payload. Screenshotter has been observed in JavaScript, Python, AutoHotKey, and AutoIT implementations. One documented JavaScript variant used a bundled legitimate IrfanView executable (for example, snap.exe or lumina.exe) to save a desktop screenshot as gs.jpg, after which another component uploaded the image to C2. TA866 appears to have used the screenshots to manually triage victims before selectively deploying additional tooling such as AHK Bot and, in some cases, Rhadamanthys. Observed C2 patterns included hardcoded IP-based HTTP endpoints such as hxxp://109[.]107.173.72/screenshot/%serial% and hxxp://193[.]233.133.179:80/screenshot/[C: Drive Serial Number]. Screenshotter has also been observed delivered alongside or as a companion to other malware including Rhadamanthys, Remcos, zgRAT, AHK Bot, BitRAT, XWorm, Lumma, and XLoader. Victimology associated with TA866 activity was concentrated in the United States, with manufacturing the most affected sector, followed by government and financial services.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA866

Screenshotter is a malware family used to generate periodic screenshots from infected systems which are transmitted to the threat actor over HTTP.

via talosintelligence otherblog.talosintelligence.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1608.006SEO PoisoningEvidence1

Prior reporting indicates that TA866 has been observed leveraging malicious Google advertisements and SEO poisoning to infect victims.

Initial Access

1 technique
T1566PhishingEvidence1

Typical distribution campaigns As previously mentioned, initial access to target environments is typically obtained by TA866 through successfully infecting systems via either malspam or malvertising.

Stealth

1 technique
T1218.007MsiexecEvidence1

Once downloaded, the MSI is passed to MsiExec to execute the next stage of the process.

Command and Control

1 technique
T1071.001Web ProtocolsEvidence1

Captured screenshots are transmitted to the attacker’s C2 server ... via HTTP POST requests.

INDICATORS OF COMPROMISE

IOCs tracked for this family

10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
hash.sha256●●●●●●●●●●●●View more in app3 years ago
hash.sha256●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching10

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

Screenshotter | Mallory