Yuze
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Stealth
1 technique
Stealth
Command and Control
4 techniques
Command and Control
Velociraptor, for command-and-control (C2). Visual Studio Code and Cloudflare Tunnel, for tunneling C2 communications. Yuze, for intranet penetration and establishing a reverse proxy connection to the attacker's C2 server across HTTP (port 80), HTTPS (port 443), and DNS (port 53).
Yuze, for intranet penetration and establishing a reverse proxy connection to the attacker's C2 server across HTTP (port 80), HTTPS (port 443), and DNS (port 53).
Cloudflare Tunnel... the attacker first registered it as a persistent Windows service... The tunnel run --token command then authenticated the compromised machine to the attacker's Cloudflare account... The TA leveraged VS Code's built-in tunneling capability to establish a covert C&C channel... Yuze... supports forward and reverse SOCKS5 proxy tunneling.
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.