Malware
TONEDEAF
TONEDEAF is a backdoor that communicates with Command and Control servers using HTTP or DNS. Supported commands include system information collection, file upload, file download, and arbitrary shell command execution. When executed, this variant of TONEDEAF wrote encrypted data to two temporary files – temp.txt and temp2.txt – within the same directory of its execution.
Indicators of Compromise 15
Domain decoraat[.]net Domain onedown[.]gesecole[.]net Filename AVK.exe Filename AVKTray.dat Filename Avk.dll Filename Invitation_Letter_No.02_2026.csproj Filename Invitation_Letter_No.02_2026.exe SHA-256 29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad SHA-256 46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc SHA-256 5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc SHA-256 6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7 SHA-256 7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b176 SHA-256 8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99 SHA-256 d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e SHA-256 de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1
MITRE ATT&CK TTPs 11
T1021.001 T1036 T1036.005 T1055 T1055.001 T1059.001 T1059.003 T1071.001 T1204.002 T1566 T1566.001
Remote Desktop Protocol
Lateral Movement
Masquerading
Defense Evasion
Match Legitimate Name or Location
Defense Evasion
Process Injection
Defense Evasion
Dynamic-link Library Injection
Defense Evasion
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
Malicious File
Execution
Phishing
Initial Access
Spearphishing Attachment
Initial Access