Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The software is broadly classified as malware by most antivirus companies, likely thanks to an advertised feature list that includes dumping the remote computer’s temporary memory; retrieving passwords from dozens of email programs; snarfing the target’s Wi-Fi credentials; and viewing the target’s Webcam.
The software is broadly classified as malware by most antivirus companies, likely thanks to an advertised feature list that includes dumping the remote computer’s temporary memory; retrieving passwords from dozens of email programs; snarfing the target’s Wi-Fi credentials; and viewing the target’s Webcam.
The software is broadly classified as malware by most antivirus companies, likely thanks to an advertised feature list that includes dumping the remote computer’s temporary memory; retrieving passwords from dozens of email programs; snarfing the target’s Wi-Fi credentials; and viewing the target’s Webcam.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote administration tool broadly classified as malware by many antivirus vendors, with features including memory dumping, password theft from email programs, Wi-Fi credential theft, webcam access, and stealthy installation options attractive to cybercriminals.
A commodity remote access trojan sold on underground forums that provides web-based command-and-control (C2) via a hosted C2-as-a-Service model, supports credential theft (browsers, email, IM, Windows/network), system reconnaissance, file browsing, remote shell/registry, persistence via Run keys, and includes features like keylogging and webcam access. Some samples also showed DNS noise (NXD lookups) and a one-off Monero mining pool contact.
A commodity remote access trojan sold on underground forums that provides web-based command-and-control, persistence, credential theft, surveillance, remote shell, registry access, file browsing, forensic collection, and other host control capabilities. The report also notes limited observed DNS-based behavior and a one-off Monero mining pool contact in at least one sample.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.