Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
La liste « Malware / Outils » de l’article cite « HVNC backdoor (backdoor) ».
24 distinct techniques documented for this family, organized by ATT&CK tactic.
UpdateAssistant.exe copies itself ... into %APPDATA%\Roaming\Programs\Common\, renaming the executable to AppUpdateHelper.exe, then drops a shortcut into the current user’s Startup folder.
The C2 host is stored as 12 raw bytes, XOR-encoded with a single byte (0x37). A second function decodes browser names using a different XOR key.
The 64-bit backdoor masquerad[es] as “Windows Update Assistant” / Microsoft Corporation in its version metadata, while unsigned.
The LNK is disguised as a tax receipt, while the unsigned payload claims to be Microsoft Corporation’s “Windows Update Assistant” and later renames itself AppUpdateHelper.exe.
The malware monitors keystrokes; static analysis found it could poll the keyboard state.
The payload contains hardcoded references to Firefox cookies.sqlite and is described as stealing Firefox cookies.
The handshake ... checks in with a full victim fingerprint — CPU model, RAM, architecture, and ... antivirus-discovery results.
Hardcoded Firefox places.sqlite and permissions.sqlite strings identify browser history and permission-store targeting.
All [capabilities communicate] over TCP/27015 ... The stream switches to a binary frame format consistent with screen-tile data.
Invoke-WebRequest ... downloads a second-stage binary and runs it.
The payload creates a hidden virtual desktop and supports screen capture plus simulated mouse and keyboard input for operator control.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.