Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

TonRAT

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.002Spearphishing LinkEvidence1

T1566.002 Phishing: Spearphishing Link Calendly notification emails carrying redirect links (observed from late May 2026)

Execution

3 techniques
T1059.001PowerShellEvidence1

T1059.001 PowerShell Obfuscated bigint decoder downloads .ps1

T1059.007JavaScriptEvidence1

T1059.007 JavaScript Node.js implant executes .js payload with C2 domain

T1204.002Malicious FileEvidence1

T1204.002 User Execution: Malicious File User opens fake image LNK ( IMG-/PHOTO-*.png.lnk )

Persistence

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence1

T1547.001 Registry Run Keys / Startup Folder Dual Run (Node.js) + RunOnce ( ProgramData EXE)

Privilege Escalation

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence1

T1547.001 Registry Run Keys / Startup Folder Dual Run (Node.js) + RunOnce ( ProgramData EXE)

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1

T1027 Obfuscated Files or Information Seven-phase PowerShell obfuscation evolution

T1036MasqueradingEvidence1

T1036 Masquerading LNK files disguised as .png images

Command and Control

1 technique
T1571Non-Standard PortEvidence1

T1571 Non-Standard Port C2 on ports 8443, 8445, 8453, 5555, 56001-56003

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

T1562.001 Disable or Modify Tools Add-MpPreference exclusions for Temp EXE files

INDICATORS OF COMPROMISE

IOCs tracked for this family

98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
79 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
19 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 day ago
domain●●●●●●●●●●●●View more in app1 day ago
domain●●●●●●●●●●●●View more in app1 day ago
domain●●●●●●●●●●●●View more in app1 day ago
domain●●●●●●●●●●●●View more in app1 day ago
domain●●●●●●●●●●●●View more in app1 day ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching98

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.