Overlord is an open-source, Go-based remote access framework used as a remote access trojan on Windows, macOS, and Linux. Its capabilities include remote shell access, screenshot capture, keystroke and clipboard collection, and file searching. Deployed variants maintain persistent WebSocket connections to command-and-control servers. A Windows build used in the MALFEX npm supply-chain campaign resolves its command-and-control address through Solana blockchain transactions and establishes persistence through a scheduled task.
MALFEX distributes Overlord through malicious npm packages whose lifecycle hooks download and execute Windows payloads. Its delivery chain includes an AutoIt-based loader with encrypted and obfuscated components. Overlord has also been deployed by UNK_DeadDrop, a developer-targeting cluster assessed as likely North Korea-aligned. That operation uses recruitment and code-review phishing lures linking to attacker-controlled GitHub and GitLab repositories, with malicious editor tasks triggering execution in Visual Studio Code or Cursor.
The modified macOS and Linux variants used by UNK_DeadDrop add browser credential theft, cryptocurrency wallet data collection, and anti-forensic cleanup. They use deceptive system-password prompts to obtain credentials needed to access macOS Keychain or Linux GNOME Keyring secrets, and archive stolen data for exfiltration. A malicious editor extension relaunches the malware to maintain persistence. These deployments target developers, particularly those working in cryptocurrency, financial services, technology, and education.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Three of the packages, "tlxbnhd," "tldriver," and "mxdriver," act as Overlord RAT loaders, with the malicious code triggered via lifecycle hooks to download and run a Windows executable.
Three of the packages, "tlxbnhd," "tldriver," and "mxdriver," act as Overlord RAT loaders, with the malicious code triggered via lifecycle hooks to download and run a Windows executable.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Delivery Arm A downloads a Windows PE payload that ultimately executes a build of overlord-client, an open-source Go RAT. The recovered build includes a live Solana blockchain C2 resolver.
The malware deployed through this campaign is cross-platform, capable of running on macOS, Linux, and Windows. It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.
On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attacker’s servers.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
The server proxies signaling so the existing JWT auth + per-client RBAC still apply... Overlord supports generic OIDC login... Local username/password login stays enabled as a fallback.
Defenders are advised to alert on persistence artifacts including the \Maiden scheduled task.
On macOS and Linux, the script installs a malicious VS Code extension (VSIX) disguised as a Google service, then launches the Overlord backdoor. ... On Linux, the malware uses ... Python scripts.
The tasks.json file launches run-update-hidden-launch.vbs via wscript.exe //B (hidden window), which calls run-update.cmd.
The tasks.json file launches run-update-hidden-launch.vbs via wscript.exe //B (hidden window), which calls run-update.cmd.
The IExpress cabinet contains a signed AutoIt3 interpreter and encrypted script; defenders are advised to alert on %LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe.
When a developer clones the repository and opens it in Visual Studio Code or Cursor, a hidden file called tasks.json inside a concealed .vscode folder automatically runs malicious scripts.
Defenders are advised to alert on persistence artifacts including the \Maiden scheduled task.
The server proxies signaling so the existing JWT auth + per-client RBAC still apply... Overlord supports generic OIDC login... Local username/password login stays enabled as a fallback.
On macOS and Linux, the script installs a malicious VS Code extension (VSIX) disguised as a Google service...
Defenders are advised to alert on persistence artifacts including the \Maiden scheduled task.
The server proxies signaling so the existing JWT auth + per-client RBAC still apply... Overlord supports generic OIDC login... Local username/password login stays enabled as a fallback.
the malware leverages the password to extract browser credentials from Keychain and GNOME Keyring and subsequently relaunches itself as root to perform further Keychain and GNOME Keyring dumps.
The loader chain uses an EA06 encrypted a3x, cycled-XOR strings, RC4 key 8448433, and LZNT1; Arm B decrypts an embedded payload using the malfexteam2027 key.
Delivery Arm A downloads a Windows PE executable disguised as image/png from a public image host. Arm B retrieves a PNG polyglot containing an embedded payload.
The infection chain finishes by deleting malicious payloads and directories from the cloned repository in an effort to clean up forensic artifacts, while maintaining persistence through the VSIX extension.
It also schedules cleanup of vendor/ and .vscode/ via a background subshell that survives editor shutdown.
The server proxies signaling so the existing JWT auth + per-client RBAC still apply... Overlord supports generic OIDC login... Local username/password login stays enabled as a fallback.
When a developer clones the repository and opens it in Visual Studio Code or Cursor, a hidden file called tasks.json inside a concealed .vscode folder automatically runs malicious scripts.
The Linux backdoor uses Zenity... to create a prompt to collect user credentials. ... a second embedded Mach-O binary named darwin-password-prompt creates a fake system dialogue to prompt the user to enter their password.
On macOS, a secondary embedded binary called darwin-password-prompt presents a fake system dialog asking the user for their device password. ... On Linux, the malware uses a native system dialog tool called Zenity to create a similar fake prompt...
The Overlord RAT first extracts browser wallet extensions and standalone wallet directories and transmits them as a ZIP archive to the C2 server.
The Windows variant targets 35 cryptocurrency wallet extensions, 18 standalone wallet applications, and browser cookies. All collected data, including wallet contents, Safe Storage keys, login credentials, and browser cookies, is packaged into a ZIP file...
After the password is collected and validated, the malware modifies browser keychain access and dumps credentials from Chrome, Brave, Edge, Opera, and several other browsers. On Linux, ... targets GNOME Keyring credentials...
The Linux backdoor uses Zenity... to create a prompt to collect user credentials. ... a second embedded Mach-O binary named darwin-password-prompt creates a fake system dialogue to prompt the user to enter their password.
Operators talk to the server through a web panel or the Electron desktop app, and agents connect over encrypted WebSockets.
Organizations should also ... monitor outbound connections for unusual traffic to unknown WebSocket endpoints.
WebRTC P2P: browser ↔ agent direct when possible, with the bundled Coturn server as a fallback for restrictive or symmetric NAT... WebRTC Relayed: agent publishes to a MediaMTX sidecar via WHIP, browser plays via WHEP.
these binaries function as full RATs with persistent WebSocket connectivity.
The recovered Overlord build includes a live Solana blockchain C2 resolver; the Solana-memo C2 channel is wired into this build as live literal strings.
282 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source remote access trojan written in Go that uses Solana transactions to obtain its command-and-control address. The MALFEX campaign delivers it to Windows systems through malicious npm package lifecycle hooks. The article later appears to refer to the same malware as "Overload RAT" when discussing separate WordPress exploitation and fake Zoom installer campaigns.
Windows remote-access trojan delivered by malicious npm installation scripts that download and execute a payload disguised as an image. It captures screenshots, keystrokes and clipboard data, searches files, provides remote shell access, and establishes persistence through a scheduled task named Maiden.
Open-source Go remote-access trojan delivered through the Arm A npm supply-chain loader chain. In this campaign, it is executed via an IExpress cabinet, signed AutoIt3 interpreter, and encrypted AutoIt script, and has a live Solana-memo/blockchain C2-resolution capability.
Cross-platform backdoor framework used to maintain persistent C2 connectivity on macOS, Linux, and Windows. In this campaign it enables remote access and supports follow-on credential theft, browser data exfiltration, and cryptocurrency wallet theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.