Agent
Agent is a generic malware/tool name used in multiple distinct contexts in the provided content rather than a single well-defined family. High-confidence references include: (1) Trojan-Downloader.AndroidOS.Agent.no, embedded in modified messaging apps and other Android app mods, which downloads Trojan-Clicker.AndroidOS.Agent.bl; the clicker opens ad URLs in an invisible WebView and uses machine learning to locate and click close buttons, inflating ad views on victims’ devices. (2) Trojan.Loader.Agent, a detection name for a malicious DLL in a multi-stage Windows loader campaign delivered via phishing emails impersonating a travel agency. That campaign abused CVE-2013-3900 to trojanize a signed WinWord.exe, side-loaded msvcr100.dll, established persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run and a scheduled task named WindowsUpdateCore, decrypted a payload hidden in the certificate area, and hollowed cvtres.exe to launch a RAT. Reported capabilities of the final payload included TLS-encrypted C2, screen capture, WMI-based host reconnaissance, file theft, active-window tracking, idle-time-based keylogging activity, privilege checks, runtime code execution, and downloading additional modules stored in the registry; reported IOCs included MD5 6CC1EAD08ADD4F967370FF1D6D07F9E1, MD5 C4C6B65C8D32B27B737E7E95ECC00D69, C2 104.37.173.244:56001, and mutexes WUCorePayload_4A8F and Ethatqehl. (3) An OS X malware context tied to CoinThief, where a RAT-like binary named Agent was installed at ~/Library/Application Support/.com.google.softwareUpdateAgent after delivery via trojanized applications such as StealthBit; it appeared responsible for sending data to remote servers and enabling remote access, and checked for Little Snitch and 1Password. (4) During Operation Wocao, threat actors used a custom proxy tool called Agent that supported multiple hops, encrypted hop IP addresses with RC4, and upgraded sockets to TLS to relay traffic. Because the content conflates several unrelated Android, Windows, macOS, and intrusion-tool usages under the same label, Agent should be treated as an ambiguous/generic name rather than a single malware family.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
IoC 표에서 악성 DLL 파일의 탐지명으로 'Trojan.Loader.Agent'가 제시되며, 전체 공격은 다단계 로더를 통해 최종 원격 제어 및 정보 탈취 모듈을 실행하는 구조로 설명됩니다.
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Credential Access
1 technique
Credential Access
Discovery
1 technique
Discovery
Collection
1 technique
Collection
Command and Control
4 techniques
Command and Control
What it does is to try to contact a remote server and download a file... $.get( settings.get('reportServer') + "/updates/firstUpdate.php" ... )
Gomir uses reverse proxy functionality that employs SSL to encrypt communications. During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket.
Recent activity
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
정상 서명된 WinWord.exe를 변조하고 CVE-2013-3900을 악용해 신뢰 검증을 우회한 뒤, DLL 사이드로딩으로 악성 DLL을 실행하고 지속성을 확보합니다. 이후 인증서 영역에 숨긴 페이로드를 복호화해 cvtres.exe에 프로세스 할로잉으로 주입하고, 최종적으로 TLS 기반 C2 통신, 화면 캡처, 시스템 정보 수집, 파일 탐색/수집, 키로깅, 추가 모듈 다운로드를 수행하는 원격 제어형 악성코드로 동작합니다.
Android banking trojan family included in the top mobile banker rankings for the quarter.
An Android banking Trojan family represented by variants such as Agent.rj and Agent.eq in the 2024 mobile banking malware rankings.
An Android mobile banking Trojan family included in the top banking trojan rankings for Q1 2026.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.