Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
It all starts with a spam email containing an XLSX attachment that exploits the Microsoft Equation Editor’s remote code execution vulnerability (CVE-2017-11882) to download the file vbs.exe hosted on an open directory, save it as svchost.exe under %AppData% directory and automatically execute it. | This then connects to a Command and Control server (C&C or C2) to which it sends the compromised system information, and requests for the Remote Access Trojan (RAT) component – XpertRAT.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Additionally, we believe a controller for yet another remote access trojan, XpertRAT, was also hosted on this IP in November 2015; however, we did not uncover any samples..."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Dumping the file from memory revealed it to be a Visual Basic compiled binary which injects into a legitimate Microsoft Internet Explorer (iexplore.exe) process.
This then connects to a Command and Control server (C&C or C2) to which it sends the compromised system information, and requests for the Remote Access Trojan (RAT) component – XpertRAT.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a suspected RAT controller hosted on the same C2 IP (88.198.222[.]163) in Nov 2015, but no corresponding malware samples were recovered in this dataset.
A RAT family mentioned because it shares C2 infrastructure with the Nanocore payload observed in the campaign.
A remote access trojan fetched from C2 as a plugin/component after initial staging. It is delivered as passwords.dll and is used to retrieve usernames and passwords stored in browser caches and emails, enabling remote access and credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.