Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We uncovered part of a new toolkit which was used as a downloader alongside Adobe Flash exploit CVE-2018-5002 to target victims in the Middle East. | We have dubbed the malware ‘CHAINSHOT’, because it is a targeted attack with several stages and every stage depends on the input of the previous one.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In October 2018, researchers at Kaspersky stumbled across SandCat after discovering an already known piece of malware called Chainshot on a victim’s machine in the Middle East.
"CHAINSHOT is an exploit kit that has previously been associated with Candiru."
"CHAINSHOT is an exploit kit that has previously been associated with Candiru."
"CHAINSHOT is an exploit kit that has previously been associated with Candiru."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The Flash application is an obfuscated downloader which creates a random 512-bit RSA key pair in memory of the process.
By doing so, the function NtProtectVirtualMemory is executed without calling it directly. This trick is likely used to bypass AVs/sandboxes/anti-exploit software which hook NtProtectVirtualMemory and the attacker probably chose NtPrivilegedServiceAuditAlarm as a trampoline as it’s unlikely to be ever be monitored.
FirstStageDropper.dll is responsible for injecting SecondStageDropper.dll into another process to execute it. While the samples we obtained inject SecondStageDropper.dll in usermode via thread injection, the x64 shellcode seems to have an option to inject it from kernelmode.
FirstStageDropper.dll is responsible for injecting SecondStageDropper.dll into another process to execute it. While the samples we obtained inject SecondStageDropper.dll in usermode via thread injection, the x64 shellcode seems to have an option to inject it from kernelmode.
The encrypted exploit or payload is sent back to the downloader which uses the in-memory private key to decrypt the AES key and the exploit or payload.
84 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit associated with Candiru used to deliver spyware; linked via shared infrastructure/fingerprints to Candiru-related delivery URLs. Reported in use by multiple threat actor groups and connected to exploitation activity enabling final-stage spyware delivery.
A previously known malware used by multiple nation-state actors in the Middle East and installed via zero-day exploits in SandCat operations.
A multi-stage targeted malware framework used alongside an Adobe Flash exploit. It decrypts staged payloads, loads an embedded FirstStageDropper.dll, gathers victim system and process information, attempts to bypass security products such as EMET, Kaspersky, and Bitdefender, injects a second-stage DLL into another process, and downloads a final payload from attacker-controlled HTTPS infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.