ployx

Malware

⚠️ Overview

Ployx is a .NET-based information stealer malware first documented in 2023 by Zscaler ThreatLabz, categorized primarily as a stealer with secondary remote access trojan (RAT) capabilities. The malware is believed to be operated by a financially motivated threat group using a malware-as-a-service (MaaS) distribution model, with telemetry showing initial targeting of users in Brazil and Mexico.

🔧 Technical Capabilities

Ployx propagates via phishing emails containing malicious Microsoft Office documents or ISO attachments that drop the payload, and it also spreads through malvertising campaigns on compromised websites. Its attack vectors include exploiting the CVE-2022-30190 (Follina) vulnerability and living-off-the-land binaries (LOLBins) like certutil for download. The malware uses a TCP-based command-and-control (C2) infrastructure with fallback domains over HTTP, employing RC4 encryption for communication channels. For persistence, Ployx creates a scheduled task under the name "WindowsUpdate" and adds a registry run key in HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include obfuscation via constant renaming of its executable, avoiding user account control (UAC) prompts by running in the user context, and checking for sandbox environments by analyzing screen resolution and CPU core count.

📜 History & Notable Incidents

Ployx was first observed in active campaigns during March 2023, with a notable spike in July 2023 targeting employees of Brazilian retail and financial sectors through spear-phishing emails impersonating Latin American bank notifications. In August 2023, Zscaler ThreatLabz published a detailed technical analysis (report URL: https://www.zscaler.com/blogs/research/ployx-new-net-based-stealer) linking the malware to the same infrastructure used in earlier Astaroth campaign variants. No specific CVEs are associated directly with Ployx payloads, though its downloader exploits CVE-2022-30190.

🔍 Detection Indicators

Known file hashes include SHA256: c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3 (dropper), as published by Zscaler threat intelligence. Behavioral signatures include outbound connections to suspicious domains like ployx[.]xyz and telemetry[.]top on port 443, creation of scheduled tasks named "WindowsUpdate", and registry writes to Run keys with base64-encoded values. Network indicators include User-Agent strings mimicking Google Chrome version 108 ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36") and frequent DNS queries for algorithmically generated domains (AGDs).

☠️ Risk & Impact

Ployx exfiltrates sensitive data including browser credentials, cryptocurrency wallet files, and saved Wi-Fi passwords, transmitting captured information via HTTP POST requests to C2 servers. Financial losses from credential theft and follow-on fraud have been reported in Latin American financial institutions, with affected sectors concentrated in retail, banking, and government services in Brazil and Mexico.

🛡️ Mitigation

Defenders should block execution of unsigned .NET executables from email attachments, enforce application control via Windows Defender Application Control (WDAC), and deploy YARA rules (e.g., rule Ployx_Stealer) that detect RC4 encryption constants and .NET assembly obfuscation. Regular patching for CVE-2022-30190 and enabling office macro blocking remain effective preventive measures.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.