Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stowaway then delivered the exfiltration piece: TmcLoader and its embedded TmcPayload. Per Kaspersky, “TmcLoader is a stealthy C++ loader module registered as a Windows service.”
9 distinct techniques documented for this family, organized by ATT&CK tactic.
This malware receives encrypted and base64-encoded command-line arguments... ThumbcacheService employs XOR encryption... TmcLoader employs dynamic API resolution through a circular XOR encryption... combined with Base64 encoding for string obfuscation.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy C++ loader registered as a Windows service that decrypts and loads its payload directly into svchost memory to evade detection.
A stealthy Windows service loader that decrypts and injects an embedded payload into svchost, uses obfuscated API resolution, and enables persistence while preparing the exfiltration component.
Stealthy C++ Windows service loader that decrypts and injects an embedded payload into svchost, uses obfuscated API resolution, and supports persistence while preparing the exfiltration component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.