VOLTMARKER is a malware payload associated with UNC4108, a threat cluster of unknown motivation. UNC4108 has deployed VOLTMARKER using PowerShell alongside NetSupport RAT and hands-on reconnaissance activity. Its specific malware classification, functionality, target platform, and distribution mechanism are not publicly established by the available evidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC4108 is described as using PowerShell to deploy VOLTMARKER and NetSupport RAT alongside hands-on reconnaissance; the observed NetSupport payload is assessed as consistent with UNC4108 tradecraft.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family associated with UNC4108 PowerShell deployment activity and mentioned alongside NetSupport RAT in the attribution context.
Payload distributed by UNC4108 (functionality not described in the provided content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.