Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
An added layering of obfuscation via junk code to obfuscate and impair forensic analysis... This malware is a .net compiled binary that has a customized obfuscation and a large amount of junk code that makes analysis harder to accomplish.
Then it will change the ownership of the registry to the current logo user and change the access control to full access to delete each of the subkeys...
Overwrites files with zero blocks of 4096 bytes... Lists system files and then proceeds to destroy them... Then it will open the target file using NtOpenFile() native API to zero or wipe it using a native API NtFsControlFile() that sends an IOCTL control code FSCTL_SET_ZERO_DATA directly to a specified file system.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.