Skip to main content
Mallory
MalwareUsed by 2 actors

VINETHORN

VINETHORN is malware associated with the Iranian threat actor APT42, also referred to in the content as Imperial Kitten. The malware was staged on APT42-controlled infrastructure and masqueraded as a VPN application, indicating delivery through social engineering and fake or impersonating software. The content also states that Imperial Kitten uses spear-phishing with malicious links to deliver VINETHORN and other malware, exploits Android vulnerabilities, and employs cloud-based command-and-control servers. High-confidence context ties VINETHORN to APT42 espionage activity targeting entities of interest to that actor, including US, Israeli, and dissident targets. The provided content does not include specific technical details on VINETHORN’s internal functionality, persistence mechanisms, or indicators of compromise beyond its staging on actor infrastructure and its disguise as a VPN app.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
APT42

APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.

via mitre attackattack.mitre.org
Magic Hound

Imperial Kitten... deliver VINETHORN malware...

via polyswarmblog.polyswarm.io
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

T1608Stage CapabilitiesEvidence2

"APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting." / "FIN7 has staged legitimate software, that was trojanized...on Amazon S3." / "TeamTNT has uploaded backdoored Docker images to Docker Hub."

T1608.001Upload MalwareEvidence1

APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.

Initial Access

1 technique
T1566PhishingEvidence1

Multiple Iran-nexus APT groups are described as using spear-phishing: e.g., Charming Kitten uses “spear-phishing with fake personas and compromised emails… phishing via benign PDFs for credential harvesting”; several others use “spear-phishing with malicious documents/attachments/links.”

Stealth

2 techniques
T1036MasqueradingEvidence3
TacticStealth

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1036.005Match Legitimate Resource Name or LocationEvidence1
TacticStealth

APT42 has masqueraded the VINETHORN payload as a VPN application.

T1573Encrypted ChannelEvidence1

Imperial Kitten is described as “using cloud-based C2 servers”; Tortoiseshell “leveraging cloud infrastructure like Azure for C2.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.