Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A second branch installed ARKTunnel, an undocumented remote-access tool that hid its payload inside a bitmap image.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“It then contacts its C2 servers via an HTTPS POST request to /d” and “POST requests to /d for tasks and POST requests to /e for error reporting.”
It created a delayed-start Windows service and could tunnel TCP or UDP traffic and run files.
“The RAT supports TCP and UDP tunneling, as well as file execution.”
OfferLoader used a trojanized Inno Setup installer to start the next stages. After a tracking check, it launched three child processes for separate malware operations.
107 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An undocumented Windows remote-access and network-tunneling tool delivered via steganography. It extracts its payload from a bitmap image, establishes a delayed-start service, tunnels TCP/UDP traffic, and executes files.
An undocumented remote-access and tunneling tool delivered through the OfferLoader chain. It conceals its payload in a bitmap image, establishes persistence through a delayed-start Windows service, can tunnel TCP and UDP traffic, and can execute files.
RAT fondé sur WebSocket, dissimulé et extrait depuis une image bitmap par stéganographie. Le contenu indique environ 50 échantillons sur plus d'un an de développement et plusieurs rotations d'identités corporatives fictives.
A payload distributed by the CL-CRI-1171 campaign through its custom loader; the content provides no further functionality details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.