Skip to main content
Mallory
MalwareUsed by 1 actor

MonsterV2

MonsterV2 is a subscription-based malware-as-a-service family advertised on cybercriminal forums since at least February 2025 and also referred to as Aurotun Stealer. It is consistently described as a multifunctional remote access trojan (RAT), stealer, loader, and backdoor. Reported capabilities include theft of browser credentials, login data, credit card data, cryptocurrency wallet data, Steam/Telegram/Discord tokens, files and documents; desktop viewing and capture; webcam recording; clipboard cryptocurrency address replacement (clipper); hidden virtual network computing (HVNC) for covert remote desktop access; command execution; and downloading/executing additional payloads. Proofpoint observed MonsterV2 loading additional malware including StealC V2 and Remcos. The malware may query api.ipify[.]org before C2 communication to obtain external IP/location and test connectivity, and it avoids infecting systems in CIS countries. Technical reporting notes configuration/C2 protection using ChaCha20 and ZLib, and frequent packing with the SonicCrypt crypter, which adds anti-analysis checks and can execute decrypted payloads via Windows Task Scheduler COM. MonsterV2 is strongly associated with TA585, which frequently delivered it in 2025 via ClickFix social-engineering campaigns using phishing lures, compromised websites with malicious JavaScript fake CAPTCHA overlays, and abused GitHub notification emails. Observed lures included IRS and U.S. Small Business Administration themes, with finance and accounting firms among targets in some campaigns. MonsterV2 has also been distributed by CastleLoader, which has delivered multiple infostealers and RATs.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA585

The main malware payload used by TA585 is MonsterV2, a backdoor, stealer and loader MaaS.

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence2

"weaponized attachments distributed via phishing emails"; "phishing email contained a ZIP file"; "malicious ICS files"; "malicious SVG files"

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.