Resident is a custom Windows backdoor associated with intrusion activity linked to TA866, also known as Asylum Ambuscade. It has been observed in campaigns targeting manufacturing, commercial, and healthcare organizations, with broader TA866 follow-on activity also affecting government and financial services, particularly in the United States. Reporting has assessed likely Russian-speaking operators behind the campaign, and code and functional overlaps with WarmCookie suggest shared authorship or common development lineage.
Resident is used after initial compromise to maintain access and enable follow-on intrusion activity. Observed delivery chains relied on phishing and drive-by download activity, including malicious JavaScript that retrieved MSI installers and staged additional components. In TA866-related activity, Resident was also delivered after earlier-stage tooling and post-compromise access had already been established.
The malware’s core role is to provide persistent remote access and deploy secondary payloads. Observed variants could download and execute additional payloads, including EXE and DLL content, and supported remote command execution. Campaign activity around Resident also included host profiling, reconnaissance, screenshot capture through companion tooling, and deployment of additional malware such as Cobalt Strike and, in at least one case, Rhadamanthys. Persistence has been established through scheduled tasks and Startup-folder shortcuts. Technical reporting also noted dynamic API resolution and RC4-obfuscated strings in at least one Resident variant.
Resident is best characterized as a backdoor used as a staging and access-enablement component within broader financially motivated intrusion chains. Its operational use, persistence mechanisms, and overlap with other TA866 tooling place it within a mature ecosystem of modular malware used for sustained access and selective follow-on payload deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As described in prior reporting, Resident is a backdoor that can be used to download and execute additional payloads on victim systems.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The persistence is achieved via a scheduled task named “RtlUpd” that runs every 10 minutes starting from the time when the binary was first executed.
when the cmd-command event is triggered, the code executes the given command from the C2 in the terminal and logs the output.
The malicious PowerShell command mentioned before retrieves and executes the PowerShell script from 31.41.244[.]142.
The threat actor(s) also performed reconnaissance with the following commands: net group “domains admins” /domain whoami /groups ipconfig /all
the script uses WScript.shell object to query the Windows Management Instrumentation (WMI) for information about active processes...
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor malware family that shares notable code/function-level similarities with WarmCookie (e.g., RC4 implementation, mutex management, persistence mechanisms), suggesting shared development lineage.
Resident is a backdoor malware family noted here for code and functional similarities with WarmCookie, including RC4 implementation, mutex handling, startup logic, and persistence via scheduled tasks.
Resident is a persistent backdoor associated with TA866 intrusions that enables download and execution of additional payloads on victim systems.
Custom backdoor used in the Resident campaign. It establishes C2 communications, achieves persistence via scheduled tasks or startup shortcuts, gathers host identifiers, can execute commands and payloads, and can deploy secondary tools including Cobalt Strike and stealers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.