Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We discovered it back in 2021, when we were investigating the CVE-2021-40449 zero-day vulnerability. At that time, we identified this backdoor as related to the IronHusky APT... | We observed the latter situation with an implant that we dubbed MysterySnail RAT. We discovered it back in 2021, when we were investigating the CVE-2021-40449 zero-day vulnerability... recently we managed to spot attempted deployments of a new version of this implant, occurring in government organizations located in Mongolia and Russia.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed the latter situation with an implant that we dubbed MysterySnail RAT. We discovered it back in 2021, when we were investigating the CVE-2021-40449 zero-day vulnerability... recently we managed to spot attempted deployments of a new version of this implant, occurring in government organizations located in Mongolia and Russia.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
One of the recent infections we spotted was delivered through a malicious MMC script, designed to be disguised as a document from the National Land Agency of Mongolia (ALAMGAC).
This file is encrypted with a single-byte XOR and is loaded at runtime. It is likely that the attackers introduced this file to the backdoor as an anti-analysis measure.
By communicating with the legitimate https://ppng.io server powered by the piping-server project, the backdoor is able to request commands from attackers and send back their execution results.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan (RAT) updated by the IronHusky group to target organizations in Russia and Mongolia.
A remote access trojan/backdoor linked in the content to IronHusky. It is used in targeted intrusions, persists as a service, loads an RC4- and XOR-encrypted payload from attach.dat, uses reflective loading/DLL hollowing, communicates with attacker-controlled HTTP servers, and supports roughly 40 commands for file management, command execution, process control, service management, and network resource access. Newer observed versions also use a modular architecture with multiple DLL modules downloaded at runtime.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.