Karagany, also known as Xfrost and commonly referred to as Trojan.Karagany, is a Windows remote access trojan used in espionage-oriented intrusions and available in underground markets. It has been associated with Dragonfly activity targeting energy, oil, and industrial control system-related organizations, including campaigns involving watering-hole compromises and trojanized software distribution. Reporting indicates the variant used in those operations was likely modified from the commodity malware base.
Karagany supports a broad set of surveillance, credential access, and host reconnaissance functions. Documented capabilities include collecting passwords, stealing data and credentials from browsers, capturing keystrokes, taking desktop screenshots, cataloging documents on infected systems, enumerating running processes, gathering user information, and collecting local network configuration details. It can create directories to stage collected data and plugin output for exfiltration, and its command-and-control communications have been observed protected with SSL/TLS. Some observed variants also support plugins with self-delete behavior, indicating anti-forensic or cleanup functionality.
For persistence, Karagany can establish automatic execution at logon by placing a shortcut in the Windows Startup folder. It has also been observed acting as a downloader in broader malware ecosystems, including downloading other malware families. Overall, Karagany is best characterized as a modular RAT used for post-compromise collection and operator access on Windows hosts, particularly in campaigns against energy-sector and ICS-adjacent targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The chaining or combination of multiple legacy vulnerability exploits with exploitation of the newer Windows Zerologon vulnerability | This group avoids using custom malware, opting for commodity malware families that hinder attempts at applying attribution... • Use of commodity malware such as Goodor, DorShel, and Karagany
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dragonfly members also infected some computers with Trojan.Karagany, a RAT available in underground markets that has most likely been modified. It’s capable of collecting passwords, taking screenshots, and cataloging documents stored on infected computers.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Russian government-sponsored threat actors have been linked to widespread router compromise campaigns in the past... The example from the Secureworks engagement appears to demonstrate how targeted threat groups such as IRON LIBERTY can weaponize their access to routers and Internet infrastructure to gain initial access to targeted systems.
These include phishing emails, redirections to compromised web sites and most recently, trojanized update installers on at least three ICSs vendor web sites, in what are referred to as watering-hole style attacks.
Dragonfly operators hacked websites of at least three different companies providing ICS software... there had already been 250 downloads of the trojanized software... In addition to trojanizing legitimate software used by its victims... the group has more recently begun infecting suppliers
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims... BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems... Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Among other things, it extracts data from a victim’s Outlook address book and virtual private networking (VPN) programs... It’s capable of collecting passwords
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Karagany is malware used by the IRON LIBERTY espionage group. In this incident, it was delivered via a trojanized Adobe Flash installer in a likely man-on-the-side attack, then installed itself under %APPDATA%\Local\SearchIndexer\ as SearchIndexer.exe and established persistence via the Startup folder. The content notes the original Karagany malware was an e-crime tool later adopted and evolved by IRON LIBERTY.
Trojan/backdoor that gathers information about the user on a compromised host.
Gathers network configuration information from compromised hosts.
Trojan malware that persists by creating a Startup-folder link to itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.