Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:43:28 UTC Home > List all groups > List all tools > List all groups using tool IronNetInjector Tool: IronNetInjector Names IronNetInjector Category Malware Type Loader Description (Palo Alto) IronNetInjector is made of an IronPython script that contains a .NET injector and one or more payloads. The payloads can be also .NET assemblies (x86/64) or native PEs (x86/64). When an IronPython script is run, the .NET injector gets loaded, which in turn injects the payload(s) into its own or a remote process. Information MITRE ATT&CK Malpedia Last change to this tool card: 22 June 2023 Download this tool card in JSON format All groups using tool IronNetInjector Changed Name Country Observed APT groups Turla, Waterbug, Venomous Bear 1996-2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=db8af4a3-93ac-429e-896d-7fe469e8d1ad https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=db8af4a3-93ac-429e-896d-7fe469e8d1ad Page 1 of 1