Supper, also known as SocksShell, ZAPCAT, and WINDYTWIST, is a Windows backdoor used to maintain access to compromised systems before ransomware deployment. First observed in July 2024, it is a small DLL-based implant that provides remote command-line execution and SOCKS5 proxying. Operators can execute shell commands, run supplied DLL payloads, and tunnel traffic through infected hosts. Supper supports scheduled-task persistence, encrypted command-and-control communications, and self-deletion; analyzed variants can receive additional command-and-control endpoints.
Supper uses extensive obfuscation and anti-analysis techniques, including API hammering, hashed API resolution, runtime shellcode reconstruction, custom decompression, and anti-debugging checks. Samples have been protected by crypters including Tomb and JunkFiction. Operators have used its remote shell to perform host, network, and Active Directory reconnaissance through PowerShell and native Windows utilities, including enumeration of domain controllers, trusts, users, and privileged groups. It has also supported hands-on-keyboard credential-access and lateral-movement activity.
Supper is associated with Vanilla Tempest and has appeared in intrusions involving Rhysida, INC, and Interlock ransomware. Deployment chains include GootLoader infections, fake CAPTCHA/ClickFix lures, and trojanized software installers distributed through fraudulent download pages, malvertising, and SEO poisoning. It has also been delivered through the pkr_mtsi packer. Its documented use includes attacks against enterprise Windows environments and U.S. healthcare organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lorem Ipsum appears to be a parallel or successor loader within Rapid Brigantine's expanding toolkit, culminating in handoff to their documented post-exploitation arsenal (Supper, Oyster, MeowBackConn) and ultimately to Rhysida ransomware deployment.
Storm-0494 deploys backdoors like Supper (SocksShell or ZAPCAT) and AnyDesk for remote access, further compromising networks.
X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
"As a persistence mechanism, the sample added itself as a Windows scheduled tasks: schtasks.exe /Create /SC MINUTE /TN GoogleUpdateTask ..."
Its main purpose is to provide threat actors with command line access to a victim (enabling “hands on keyboard” activity).
"The operators used PowerShell and native Windows utilities to identify the domain, enumerate machines, discover domain controllers and examine privileged groups."
The operators used "nltest /dclist:<domain>" and PowerShell "DirectoryServices.DirectorySearcher" to enumerate domain computers.
"The ability to proxy traffic through the infected machine allows threat actors to map the internal network stealthily"
"Other supported commands include, at minimum, a SOCKS proxy feature"; YARA strings include "bad socks5 request" and "Starting Init SOCKS"
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Persistent post-compromise backdoor in the Rhysida-related ecosystem. Operators used it for hands-on-keyboard activity, including Active Directory, domain-controller, domain-trust, privileged-group, system, and network discovery.
A custom backdoor reportedly used by Vanilla Tempest to establish an initial foothold before ransomware deployment. It is mentioned because a prior Supper case used the same Active Directory account-enumeration query observed in this activity.
A backdoor used by both Interlock and Rhysida that maintains persistent access, creates encrypted tunnels, and executes remote shell commands. IBM found it shares command structures, C2 registration formats, and self-deletion behavior with InterlockRAT.
A post-exploitation SOCKS5 backdoor/tool in Rapid Brigantine's arsenal, mentioned as downstream tooling associated with Lorem Ipsum-enabled intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.