Karagany, also known as Trojan.Karagany and xFrost, is a Windows remote access trojan available through underground markets and used by the Dragonfly threat group. It has been deployed in watering-hole attacks targeting the energy and oil sectors, including activity associated with the Lightsout exploit kit.
Karagany supports password dumping, theft of browser credentials and data, keystroke capture, desktop screenshots, and document inventory. It gathers information about users and local network configuration and can enumerate running processes using the Windows Tasklist utility. Its plugin-based functionality includes self-deletion capabilities that support cleanup and defense evasion. It creates directories to store plugin output and stage collected data for exfiltration, and establishes persistence through a shortcut in the Windows Startup folder. Some Win32/Karagany variants have also been observed downloading FakeRean rogue security software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The chaining or combination of multiple legacy vulnerability exploits with exploitation of the newer Windows Zerologon vulnerability | This group avoids using custom malware, opting for commodity malware families that hinder attempts at applying attribution... • Use of commodity malware such as Goodor, DorShel, and Karagany
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dragonfly members also infected some computers with Trojan.Karagany, a RAT available in underground markets that has most likely been modified. It’s capable of collecting passwords, taking screenshots, and cataloging documents stored on infected computers.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Dragonfly operators hacked websites of at least three different companies providing ICS software... there had already been 250 downloads of the trojanized software... In addition to trojanizing legitimate software used by its victims... the group has more recently begun infecting suppliers
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password, from the operating system and software.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Karagany is malware used by the IRON LIBERTY espionage group. In this incident, it was delivered via a trojanized Adobe Flash installer in a likely man-on-the-side attack, then installed itself under %APPDATA%\Local\SearchIndexer\ as SearchIndexer.exe and established persistence via the Startup folder. The content notes the original Karagany malware was an e-crime tool later adopted and evolved by IRON LIBERTY.
Trojan/backdoor that gathers information about the user on a compromised host.
Gathers network configuration information from compromised hosts.
Trojan malware that persists by creating a Startup-folder link to itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.