Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One such tool is a USB propagating worm that we have named LitterDrifter. The LitterDrifter worm is written in VBS and has two main functionalities: automatic spreading over USB drives, and communication with a broad, flexible set of command-and-control servers.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution, the module queries the computer’s logical drives using Windows Management Instrumentation (WMI)... If there isn’t an existing config file, the malware switches gears and pings one of Gamaredon’s domains using a WMI query
After creating these files, the malware proceeds to set scheduled tasks for each of the 2 components, ensuring they are regularly executed.
After creating these files, the malware proceeds to set scheduled tasks for each of the 2 components, ensuring they are regularly executed.
After creating these files, the malware proceeds to set scheduled tasks for each of the 2 components, ensuring they are regularly executed.
The orchestration component (referred to as DEOBFUSCODER) is heavily obfuscated and is constructed from a series of strings with character substitution obfuscation.
Those two functionalities reside within an orchestration component saved to disk as “trash.dll”, which is actually a VBS, despite its file extension name... Both the tasks and the startup entries are disguised using technical-sounding names such as “RunFullMemoryDiagnostic” and “ProcessMemoryDiagnosticEvents”
Before attempting to contact a C2 server, the script checks the %TEMP% folder for an existing C2 configuration file with a meaningless name that’s hardcoded in the malware. This mechanism acts as a self-check for the malware, verifying whether it already infected the machine.
To ensure its persistence, the Deobfuscoder makes a copy of the original script to a hidden file called “trash.dll” in the user’s directory... In addition to generating the shortcut, the function also creates a hidden copy of “trash.dll” in the subfolder.
Before attempting to contact a C2 server, the script checks the %TEMP% folder for an existing C2 configuration file with a meaningless name that’s hardcoded in the malware. This mechanism acts as a self-check for the malware, verifying whether it already infected the machine.
With the IP address in hand, LitterDrifter constructs the IP into a URL. The format is usually along the lines of http://<cncIP>/jaw<random_2_digit_number>/index.html=?<random_2_digit_number> . The C2 communication is carried out using a custom user-agent
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Name used by Check Point for the Gamaredon worm component later unified here as GammaWorm.
Referenced as a separate malware analysis title in the list, not central to the Gamaredon-focused content.
A VBS-based self-propagating USB worm used by Gamaredon to spread via removable drives, maintain persistence, resolve and contact rotating C2 infrastructure, and execute payloads received from the C2. It uses hidden copies of 'trash.dll', LNK decoys, scheduled tasks, Registry Run keys, WMI-based domain resolution, and a Telegram channel as backup C2 discovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.