Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other tools linked to the actor in previous attacks include Slapstick, Tinyshell, Steelhound, Steelcorgi, Wingjook, Wingcrack, Binbash, Wiperight, and the Mignogcleaner, all of which Mandiant confirmed as still deployed in LightBasin attacks.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor employed multiple obfuscation techniques, including payload and string encryption.
STEELCORGI is a packer used to encrypt malware used by the attackers.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware/tool linked to LightBasin and confirmed by Mandiant as still deployed in LightBasin attacks.
Encrypts and packages malicious payloads, transferring execution to the unpacked payload after successful decryption. Supported key sources include embedded data, console passwords, files, command-line arguments, and environment variables. It protected SUN4ME and TINYSHELL payloads in the investigated intrusions. Reuse of decryption keys and environment-variable names across separate banks helped researchers link the incidents to UNC2891.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.