Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently, we found evidence that the developers who created the Sakabota tool, which was previously discussed in the xHunt campaign, had carried out two sets of testing activities in July and August 2018 on Sakabota in an attempt to evade detection.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The cheat sheet also provides several examples of SQL injection techniques with a ticular focus on XAMPP servers.
WMIC with Bat Provides an example windows management interface command (WMIC) with arguments to run a batch script... Sakabota’s remotes tab... allows the actor to use Windows Management Instrumentation (WMI) to run commands on remote systems
The cheat sheet also suggests the actors will use scheduled tasks for persistence... The scheduled tasks in the examples have the names 'WindowsUpdateTolkit' and 'WindowsUpdateTolkit_1'... The -Rev-loop command attempts to continually create an SSH tunnel... by creating a scheduled task named update.windows
The cheat sheet also suggests the actors will use scheduled tasks for persistence... The scheduled tasks in the examples have the names 'WindowsUpdateTolkit' and 'WindowsUpdateTolkit_1'... The -Rev-loop command attempts to continually create an SSH tunnel... by creating a scheduled task named update.windows
WDigest Provides the command line commands to use the 'reg' application to query and modify the WDigest registry key 'UseLogonCredential'... the cheat sheet provides the 'reg' command to set this key to '1' to enable it.
The cheat sheet also suggests the actors will use scheduled tasks for persistence... The scheduled tasks in the examples have the names 'WindowsUpdateTolkit' and 'WindowsUpdateTolkit_1'... The -Rev-loop command attempts to continually create an SSH tunnel... by creating a scheduled task named update.windows
the actor would likely make these pivots to other systems by performing credential dumping from the Windows registry and process memory.
LSASS Process Provides five example commands that use ProcDump, Mimikatz and PowerSploit's Out-Minidump function to dump the 'lsass.exe' process memory.
Ntds Provides example commands to save the 'Security Account Manager' (SAM) registry hive using the 'reg' application and Mimikatz's 'lsadump::sam' command.
The ‘ NTDS ’ portion allows an actor to obtain a copy of a domain controller by creating an installation media using the ‘ ntdsutil ’ application... to take a snapshot of the domain controller
the following commands within the auto-complete suggestions... such as gathering information on the user and network interfaces; ... ipconfig/all
Scan For Provides three commands that use for loops to scan a local subnet... to locate systems responding to ping requests... and to check for systems whose 'C:' drive is shared
This tab also allows the actor to scan IP addresses for specific services such as RDP, SMB, FTP, HTTP(s), telnet, and SSH. This tab also allows the actor to perform TCP port scan for systems on specified network ranges
This tab allows the actor to use an embedded ‘dsquery’ tool... to query Active Directory to gather information on computers, user and groups attached to the domain.
RDP NLA Provides a PowerShell command that disables Network Level Authentication (NLA) for RDP... The cheat sheet also has two 'reg' commands... to enable RDP sessions. | The commands also suggest that the threat group heavily relies on RDP to interact with compromised hosts, likely using secure shell (SSH) tunnels created with the Plink tool between the infected system and an actor-controlled domain.
These tools not only use HTTP for their command and control (C2) channels, but certain variants of these tools use DNS tunneling or emails to communicate with their C2 as well.
The -Rev command saves an embedded PuTTY Link tool... and uses this tool... to create an SSH tunnel to allow the actor to create a remote RDP session on the system.
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom xHunt tool referenced in the actor's toolkit; associated with an operator "cheat sheet" documenting execution, credential dumping (mimikatz), brute force (thc-hydra), and other tradecraft.
A tool developed and exclusively used by the xHunt actor. In this content it is referenced for containing a cheat sheet with example Plink SSH tunneling commands and credentials reused by the actor during BumbleBee operations.
A malware tool used in the xHunt campaign for post-exploitation activities including network reconnaissance, credential dumping, remote command execution, file archiving and FTP upload, establishing SSH tunnels for RDP access, installing a webshell, and deploying additional payloads.
Earlier backdoor and likely codebase predecessor to Hisoka. It shares substantial code, strings, and developer artifacts with Hisoka, Gon, and EYE, and appears to underpin the broader xHunt toolset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.