Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The shortcut subsequently executes the VBScript through cscript, launches the downloaded PowerShell file with a hidden window and deletes both temporary files.
This incident involved a victim accessing a Bollywood pirate movie download site. When attempting to download a video, the victim was directed to a page hosted on Bunny CDN that provided a bit[.]ly link that ultimately download a ZIP file.
When we extracted the HTA code from the original fake PGP key file, the code was heavily obfuscated and even inside the HTA code there were random non-printable character sequences... There were four layers of obfuscation.
IDATLOADER will inject shellcode into pla.dll that will then extract a PNG resource from the Delphi file... From this PNG, the payload is extracted, a stealer.
The larger physicsdesc.map file is approximately 1.36 MB... The file is not a valid image, but enough of the internal PNG chunk structure is retained for the shellcode to parse it.
The infection hinged around utilizing Microsoft’s mshta.exe to execute code buried deep within a specially crafted file masquerading as a PGP Secret Key.
IDATLOADER will inject shellcode into pla.dll that will then extract a PNG resource from the Delphi file and move it into the Temp folder.
The following data is decoded by adding the key to each 32-bit value... The XOR output is then decompressed using: RtlDecompressBuffer
The LNK file was using mshta.exe to execute what appeared to be a “PGP Secret Key,” hosted again hosted on Bunny CDN.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modern loader family used to deliver Carbanak in 2024-2025.
A Delphi loader that injects shellcode into pla.dll, extracts a PNG resource, and unpacks the final stealer payload from it.
Loader that stores its malicious payload in the IDAT chunk of PNG files and is used to distribute additional malware; observed using techniques such as BPL sideloading and PNG-based steganography/encapsulation to evade detection.
A malware loader delivered through a heavily obfuscated infection chain abusing mshta.exe, a fake PGP Secret Key file, and BPL sideloading to decrypt and deploy a payload that ultimately leads to information-stealing malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.