SPIVY is a Poison Ivy remote access trojan variant observed in 2016 in targeted espionage activity against pro-democracy organizations and supporters in Hong Kong. It preserves core Poison Ivy code and behavior while introducing updated execution and command-and-control mechanisms, indicating a retooled lineage rather than a wholly distinct malware family.
SPIVY was delivered through weaponized Microsoft Office documents exploiting CVE-2015-2545 in spearphishing campaigns. The lure material was themed around contemporary Hong Kong political events and organizations, consistent with highly targeted collection against civil society and political-interest targets. After exploitation, the infection chain used DLL sideloading with a legitimate signed executable and a malicious DLL to decode and launch an obfuscated Poison Ivy shellcode payload.
Functionally, SPIVY operates as a classic RAT/backdoor in the Poison Ivy tradition. Analysis linked it directly to older Poison Ivy families through code reuse and retained implementation details such as the API call table generation approach. Its most notable evolution was in network communications: SPIVY altered the Poison Ivy challenge-response handshake by prepending pseudo-random padding and control bytes before the standard handshake structure, while leaving the remainder of the protocol largely unchanged. This modification likely served to hinder straightforward protocol recognition and detection.
SPIVY has been associated with targeted intrusion activity overlapping with clusters tracked around Hong Kong-focused spearphishing in 2016, and reporting has also referenced its use alongside other TA428-associated RATs. High-confidence reporting supports its role as a Windows-based espionage malware family used for covert remote access in politically motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Unit 42 observed this new Poison Ivy variant we’ve named SPIVY being deployed via weaponized documents leveraging CVE-2015-2545. | In March, Unit 42 observed this new Poison Ivy variant we’ve named SPIVY being deployed via weaponized documents leveraging CVE-2015-2545.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
しかし、TA428が使う他のRAT(SPIVYやCotx RAT)とは異なり、観測数は極めて少なく、これまでほとんど知られていませんでした。
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The Poison Ivy builder has an output format option of either PE file or shellcode, and in this case the backdoor was built as shellcode and then obfuscated to help prevent detection.
Decoy documents are a common technique used by many actors to trick victims into believing they have opened legitimate files from spear phishing e-mails. The attacker sends a malicious file which infects the host with malware and then displays a clean document which contains content the victim is expecting to see.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TA428が使う他のRATとして比較目的でのみ言及。
SPIVY refers to a set of attacks using PoisonIvy backdoor variants delivered via spear-phishing emails exploiting CVE-2015-2545, targeting organizations in Hong Kong.
Mentioned only as a prior blog/reference involving similar exploit documents.
A new Poison Ivy RAT variant used in targeted attacks against Hong Kong pro-democracy organizations and supporters. It is deployed via weaponized documents, uses DLL sideloading/search order hijacking, loads an encoded shellcode backdoor, and modifies the traditional Poison Ivy network handshake to hinder detection while preserving core Poison Ivy functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.