Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“When a user opens the internet shortcut file, it exploits CVE-2024-21412 to evade Microsoft Defender SmartScreen and triggers the execution of the LNK file hosted on the same WebDAV share.” The content also uses CVE-2024-21212 once for this same infection step; this appears to be a typographical error rather than a separate vulnerability.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The shortcut subsequently executes the VBScript through cscript, launches the downloaded PowerShell file with a hidden window and deletes both temporary files.
This incident involved a victim accessing a Bollywood pirate movie download site. When attempting to download a video, the victim was directed to a page hosted on Bunny CDN that provided a bit[.]ly link that ultimately download a ZIP file.
The above PowerShell script decrypts the AES-encrypted blocks to load another PowerShell script.
IDATLOADER will inject shellcode into pla.dll that will then extract a PNG resource from the Delphi file... From this PNG, the payload is extracted, a stealer.
The larger physicsdesc.map file is approximately 1.36 MB... The file is not a valid image, but enough of the internal PNG chunk structure is retained for the shellcode to parse it.
The infection hinged around utilizing Microsoft’s mshta.exe to execute code buried deep within a specially crafted file masquerading as a PGP Secret Key.
The attack chain utilizes DLL sideloading and IDATLoader to inject the final payload into explorer.exe.
The following data is decoded by adding the key to each 32-bit value... The XOR output is then decompressed using: RtlDecompressBuffer
The LNK file was using mshta.exe to execute what appeared to be a “PGP Secret Key,” hosted again hosted on Bunny CDN.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modern loader family used to deliver Carbanak in 2024-2025.
A Delphi loader that injects shellcode into pla.dll, extracts a PNG resource, and unpacks the final stealer payload from it.
Loader that stores its malicious payload in the IDAT chunk of PNG files and is used to distribute additional malware; observed using techniques such as BPL sideloading and PNG-based steganography/encapsulation to evade detection.
Loader used in the campaign's later delivery stages. An installer drops legitimate executables, supporting DLLs, a malicious sideloaded DLL, and an encrypted IDATLoader component. The malicious DLL retrieves and decrypts the loader content, supporting injection of the final Lumma or Meduza Stealer payload into explorer.exe. CVE-2024-21412 enables the upstream delivery chain; the article does not describe IDATLoader itself exploiting the vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.