Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Hologram decodes an embedded PowerShell payload (Base64 + XOR, key 44)... with every cmdlet name string-fragmented at runtime to defeat static PS1 detection rules.
hologram.yar : Yara rules to identify the Hologram/Pathfinder dropper, Stealth Packer implant, packed in-memory loader, and Telegram-bot dropper components
The dropper’s manifest doesn’t hide the intent: “Hologram – Decoy entity generator for tactical misdirection.” ... presents an installation GUI, including UAC elevation prompt framed as necessary for driver installation
Before any malicious logic runs, the binary works through a multi-tier anti-VM check... VirtualBox BIOS strings, sandbox-associated DLLs, VM MAC prefixes... scored against a real-user hardware profile... the dropper then waits for actual mouse movement before proceeding.
The first pass is instant: VirtualBox BIOS strings, sandbox-associated DLLs, VM MAC prefixes, and blacklisted usernames abort execution immediately. What passes that check is then scored against a real-user hardware profile—GPU type, core count, RAM, disk size, process count, screen resolution.
Before any malicious logic runs, the binary works through a multi-tier anti-VM check... VirtualBox BIOS strings, sandbox-associated DLLs, VM MAC prefixes... scored against a real-user hardware profile... the dropper then waits for actual mouse movement before proceeding.
The first pass is instant: VirtualBox BIOS strings, sandbox-associated DLLs, VM MAC prefixes, and blacklisted usernames abort execution immediately. What passes that check is then scored against a real-user hardware profile—GPU type, core count, RAM, disk size, process count, screen resolution.
virtnetwork.exe beacons at rapid intervals (~5–30s)... multipart/form-data POST over HTTPS/TLS 1.3, spoofing a Mac Firefox User-Agent
virtnetwork.exe opens the primary C2 channel... over HTTPS... The dropper itself makes a secondary check-in – a GET request to mikolirentryifosttry.info/api/check/ over HTTPS
The operator abuses Azure DevOps, Telegram, and Hookdeck as infrastructure—legitimate services inside most enterprise allowlists. | The implant resolves its primary C2 domain from a Telegram channel description before any of the stage 2 modules run.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based dropper delivered via a fake OpenClaw installer. It uses anti-VM and anti-sandbox checks, disables Defender protections, opens firewall ports, retrieves payloads and passwords from dead-drop infrastructure, and deploys a modular stage-2 framework aimed at credential theft from crypto wallet and password manager extensions.
A Rust-based dropper delivered via a fake OpenClaw installer. It uses anti-VM and anti-sandbox checks, executes an obfuscated PowerShell stage, disables Defender protections, opens firewall ports, retrieves payloads and passwords from dead-drop infrastructure, and deploys a modular stage-2 implant framework aimed at credential theft from crypto wallet and password manager extensions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.