CASHY200 is a PowerShell-based backdoor associated with the xHunt espionage campaign. It has been used primarily against organizations in Kuwait, including government as well as shipping and transportation entities, and has been linked to activity spanning at least 2018 through 2019. Snugy is a known variant of CASHY200 used in later xHunt intrusions.
CASHY200’s defining feature is its command-and-control channel over DNS tunneling. The malware sends encoded data in crafted DNS A-record queries and receives tasking through values embedded in IPv4 responses. It supports beaconing, command retrieval, execution of operator-supplied commands, and exfiltration of command output through sequenced DNS requests. Observed functionality includes collecting host information and executing arbitrary shell commands, then returning results through the DNS tunnel.
The malware has been delivered through multiple mechanisms in xHunt operations. Document-based lures themed around Kuwaiti government organizations were used to install PowerShell payloads, and executable droppers such as Sakabota were also used to deploy CASHY200. In compromised environments, operators established persistence with scheduled tasks and used the malware as part of broader post-compromise activity.
CASHY200 is part of a wider xHunt toolset that includes Sakabota, TriFive, Snugy, and BumbleBee. Infrastructure overlap and deployment patterns tie it closely to xHunt’s long-running targeting of Kuwaiti organizations. Its use of DNS as a covert transport reflects an emphasis on stealthy command execution and data theft while blending malicious traffic into routine name-resolution activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we observed one of these overlapping domains, specifically, windows64x[.]com, being used as the C2 server for a new PowerShell based backdoor that we’ve named CASHY200. This PowerShell backdoor used DNS tunneling to communicate with its C2 server
12 distinct techniques documented for this family, organized by ATT&CK tactic.
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
The cheat sheet also suggests the actors will use scheduled tasks for persistence... The scheduled tasks in the examples have the names 'WindowsUpdateTolkit' and 'WindowsUpdateTolkit_1'... The -Rev-loop command attempts to continually create an SSH tunnel... by creating a scheduled task named update.windows
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
The cheat sheet also suggests the actors will use scheduled tasks for persistence... The scheduled tasks in the examples have the names 'WindowsUpdateTolkit' and 'WindowsUpdateTolkit_1'... The -Rev-loop command attempts to continually create an SSH tunnel... by creating a scheduled task named update.windows
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
The cheat sheet also suggests the actors will use scheduled tasks for persistence... The scheduled tasks in the examples have the names 'WindowsUpdateTolkit' and 'WindowsUpdateTolkit_1'... The -Rev-loop command attempts to continually create an SSH tunnel... by creating a scheduled task named update.windows
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell backdoor family used by xHunt; supports network communication and system interaction, is commonly persisted via scheduled tasks, and has been observed using cmd.exe/ping to generate DNS queries consistent with DNS-based C2/tunneling behaviors.
A backdoor previously used in xHunt attacks that communicates over DNS tunneling and supports commands such as obtaining the hostname and running commands.
A PowerShell-based backdoor associated with the xHunt campaign that Sakabota can install via its Agent functionality.
A custom PowerShell-based backdoor used in the xHunt campaign that communicates with its command-and-control server via DNS tunneling. It parses commands embedded in DNS A-record responses, executes commands such as hostname and arbitrary shell commands, and exfiltrates results back through crafted DNS queries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.