Skip to main content
Mallory
MalwareUsed by 1 actor

TOTPGuard

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Magic Hound

TOTPGuard is the name of the .NET implant family... Local ildasm of that sample recovers a coherent bespoke TOTPGuard namespace... Execution runs through TOTPGuard.MyAppDomainManager ... so the managed implant executes under the trusted EbixExam.Desktop WPF process.

via github gist webgist.github.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.003Spearphishing via ServiceEvidence1

Nimbus Manticore APT operation that abuses a fake Ebix recruitment portal to deliver custom malware to job seekers. Victims are steered through a counterfeit hiring workflow at ebix.recruitment-flow.com, handed Airbus- and Ebix-branded job-description lure PDFs, and prompted to install a "two-factor authentication app" shipped as TOTPGuard.zip.

Execution

1 technique
T1574Hijack Execution FlowEvidence1

Execution runs through TOTPGuard.MyAppDomainManager, an AppDomain-hijacking class loaded via the abused EbixExam.Updater.ServiceHub carrier so the managed implant executes under the trusted EbixExam.Desktop WPF process, wired in through setup.exe and UpdateConfig.xml.

Stealth

3 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

The C2 configuration sits in encrypted EncData / SecretStorage and the live endpoint is not cleanly recoverable from the IL, a stated blind spot leaving the Azure-typosquat updater domain as the only attested network indicator.

T1036MasqueradingEvidence1
TacticStealth

The archive drops a payload set in which a malicious .NET implant masquerades inside the legitimate EbixExam.Desktop WPF application, executing through its updater service.

T1574Hijack Execution FlowEvidence1

Execution runs through TOTPGuard.MyAppDomainManager, an AppDomain-hijacking class loaded via the abused EbixExam.Updater.ServiceHub carrier so the managed implant executes under the trusted EbixExam.Desktop WPF process, wired in through setup.exe and UpdateConfig.xml.

T1071Application Layer ProtocolEvidence1

Command-and-control runs over an Azure-typosquat domain, business-joiners-exam.azurewebsiets.net, reached by the abused updater component.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

SHA-256 of main.dll, the native implant used for persistence, C2 communication, and data exfiltration.

INDICATORS OF COMPROMISE

IOCs tracked for this family

14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
10 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching14

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.