Volatility Framework
Volatility Framework is an open-source memory forensics framework referenced as part of the tooling used by the threat cluster CL-UNK-1068 (reported by Palo Alto Networks Unit 42). In the described intrusions, the actor used memory-dumping workflows (including DumpIt and DumpItForLinux) in combination with Volatility Framework to extract password hashes from memory as part of credential theft operations. The broader campaign context indicates CL-UNK-1068 targeted organizations across South, Southeast, and East Asia (including telecommunications, energy, technology, pharmaceuticals, government, law enforcement, and aviation) and operated across both Windows and Linux environments, with credential theft and sensitive data exfiltration assessed as strongly suggestive of espionage. No specific Volatility-related indicators of compromise (e.g., hashes, filenames, command lines) are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Memory forensics framework used to analyze memory dumps, supporting credential theft and sensitive data collection workflows.
Memory forensics framework used to analyze memory dumps and extract artifacts such as credential material.
Memory forensics framework used to analyze RAM images and extract artifacts such as credential material and process data.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.