Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We uncovered part of a new toolkit which was used as a downloader alongside Adobe Flash exploit CVE-2018-5002 to target victims in the Middle East.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“CHAINSHOT is an exploit kit that has previously been associated with Candiru. It has been observed in use by threat actor groups such as Stealth Falcon and SandCat, the latter believed to be linked to the Uzbek government.”
“CHAINSHOT is an exploit kit that has previously been associated with Candiru. It has been observed in use by threat actor groups such as Stealth Falcon and SandCat, the latter believed to be linked to the Uzbek government.”
"CHAINSHOT is an exploit kit that has previously been associated with Candiru."
"CHAINSHOT is an exploit kit that has previously been associated with Candiru."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The Flash application is an obfuscated downloader which creates a random 512-bit RSA key pair in memory of the process.
By doing so, the function NtProtectVirtualMemory is executed without calling it directly. This trick is likely used to bypass AVs/sandboxes/anti-exploit software which hook NtProtectVirtualMemory and the attacker probably chose NtPrivilegedServiceAuditAlarm as a trampoline as it’s unlikely to be ever be monitored.
FirstStageDropper.dll is responsible for injecting SecondStageDropper.dll into another process to execute it. While the samples we obtained inject SecondStageDropper.dll in usermode via thread injection, the x64 shellcode seems to have an option to inject it from kernelmode.
FirstStageDropper.dll is responsible for injecting SecondStageDropper.dll into another process to execute it. While the samples we obtained inject SecondStageDropper.dll in usermode via thread injection, the x64 shellcode seems to have an option to inject it from kernelmode.
The encrypted exploit or payload is sent back to the downloader which uses the in-memory private key to decrypt the AES key and the exploit or payload.
84 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit associated with Candiru used to deliver spyware; linked via shared infrastructure/fingerprints to Candiru-related delivery URLs. Reported in use by multiple threat actor groups and connected to exploitation activity enabling final-stage spyware delivery.
A previously known malware used by multiple nation-state actors in the Middle East and installed via zero-day exploits in SandCat operations.
A multi-stage targeted malware framework used alongside an Adobe Flash exploit. It decrypts staged payloads, loads an embedded FirstStageDropper.dll, gathers victim system and process information, attempts to bypass security products such as EMET, Kaspersky, and Bitdefender, injects a second-stage DLL into another process, and downloads a final payload from attacker-controlled HTTPS infrastructure.
A multistage malware toolkit delivered through malicious Excel documents and an Adobe Flash exploit. Its shellcode loads FirstStageDropper.dll, which collects and encrypts system and process information and injects SecondStageDropper.dll into another process. The second-stage downloader checks for security software and attempts to retrieve a final implant over HTTPS; researchers could not obtain that final payload. CHAINSHOT includes security-product detection and bypass logic, custom error reporting, and tightly interdependent execution stages. Researchers decrypted captured payloads because the delivery chain used insecure 512-bit RSA keys. Embedded kernel-mode shellcode suggested an alternative injection capability, but its execution and exact purpose were not established.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.