SYMBOLCOMMON_NAMEaka. SYNONYMS
win.apple_chris (Back to overview)

AppleChris

Actor(s): CL-STA-1087

VTCollection    

According to Unit 42, AppleChris is a custom Windows backdoor implemented as multiple Portable Executable (PE) binaries (EXEs and DLLs) that support flexible deployment, including DLL hijacking via the Volume Shadow Copy Service. It provides comprehensive remote access capabilities such as drive and directory enumeration, file upload/download/deletion, process listing and creation, and interactive shell execution, all controlled over HTTP using custom verbs and RSA/AES-encrypted C2 traffic. AppleChris uses a dead drop resolver design where C2 IPs are dynamically retrieved and decrypted, initially via a dual Dropbox + Pastebin mechanism (Dropbox variant) and later via a streamlined Pastebin-only approach (Tunneler variant). The newer Tunneler variant additionally introduces a proxy tunneling command that creates reverse TCP tunnels for network pivoting, while employing delayed execution and mutex-based single-instance checks to evade detection.

References
2026-03-12 ⋅ Palo Alto Networks Unit 42 ⋅ Lior Rochberger, Yoav Zemah
Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia
AppleChris CL-STA-1087
Yara Rules
[TLP:WHITE] win_apple_chris_auto (20260917 | Detects win.apple_chris.)
rule win_apple_chris_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.apple_chris."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.apple_chris"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488d0504a30900 488903 488d7320 4889742448 410fb600 8806 498b4008 }
            // n = 7, score = 100
            //   488d0504a30900       | cmp                 byte ptr [eax + ecx], 0
            //   488903               | jne                 0x1780
            //   488d7320             | dec                 eax
            //   4889742448           | mov                 eax, dword ptr [esp + 0x88]
            //   410fb600             | dec                 esp
            //   8806                 | lea                 ecx, [esp + 0xac]
            //   498b4008             | inc                 esp

        $sequence_1 = { 0f2845e7 488d15d0370900 488d4de7 660f7f45e7 e8???????? 488d55e7 488d4dd7 }
            // n = 7, score = 100
            //   0f2845e7             | lea                 edx, [0x3cf72]
            //   488d15d0370900       | dec                 eax
            //   488d4de7             | mov                 ecx, ebx
            //   660f7f45e7           | dec                 eax
            //   e8????????           |                     
            //   488d55e7             | lea                 edx, [0x3cf76]
            //   488d4dd7             | dec                 eax

        $sequence_2 = { eb12 8b442474 8b4c244c 03c8 8bc1 8944244c eb8e }
            // n = 7, score = 100
            //   eb12                 | dec                 eax
            //   8b442474             | mov                 dword ptr [ebx], eax
            //   8b4c244c             | nop                 
            //   03c8                 | xor                 eax, eax
            //   8bc1                 | dec                 eax
            //   8944244c             | mov                 dword ptr [esp + 0x58], eax
            //   eb8e                 | dec                 eax

        $sequence_3 = { 488d156a720600 488d4c2428 e8???????? 90 33c0 4889442458 4889442460 }
            // n = 7, score = 100
            //   488d156a720600       | mov                 dword ptr [esp + 0x28], ebx
            //   488d4c2428           | dec                 eax
            //   e8????????           |                     
            //   90                   | mov                 dword ptr [esp + 0x20], ebx
            //   33c0                 | dec                 ebp
            //   4889442458           | mov                 ecx, edi
            //   4889442460           | dec                 esp

        $sequence_4 = { 488d05f8d20c00 4889442420 4c8d4c2454 4c8d8424a0010000 ba00040000 488d8c24c0060000 e8???????? }
            // n = 7, score = 100
            //   488d05f8d20c00       | mov                 ecx, ebx
            //   4889442420           | dec                 eax
            //   4c8d4c2454           | mov                 ecx, ebx
            //   4c8d8424a0010000     | dec                 eax
            //   ba00040000           | lea                 edx, [0x3cf7c]
            //   488d8c24c0060000     | dec                 eax
            //   e8????????           |                     

        $sequence_5 = { 90 33c0 4889442458 4889442460 488d05fcbd0400 4889442450 c744246800000000 }
            // n = 7, score = 100
            //   90                   | test                al, al
            //   33c0                 | jne                 0x788
            //   4889442458           | jne                 0x791
            //   4889442460           | dec                 eax
            //   488d05fcbd0400       | lea                 eax, [0x56705]
            //   4889442450           | dec                 eax
            //   c744246800000000     | mov                 dword ptr [esp + 0x58], eax

        $sequence_6 = { 488b11 4c8b45e7 498bf8 33c0 488bca f348ab 498bc8 }
            // n = 7, score = 100
            //   488b11               | dec                 eax
            //   4c8b45e7             | mov                 eax, dword ptr [0x58]
            //   498bf8               | mov                 edx, 4
            //   33c0                 | dec                 eax
            //   488bca               | mov                 ecx, dword ptr [eax + ecx*8]
            //   f348ab               | dec                 eax
            //   498bc8               | lea                 edi, [0xd835d]

        $sequence_7 = { 418d5602 488d4de0 e8???????? 90 41be03000000 4489b590000000 488d55e0 }
            // n = 7, score = 100
            //   418d5602             | sub                 esp, 0xf8
            //   488d4de0             | dec                 eax
            //   e8????????           |                     
            //   90                   | mov                 dword ptr [esp + 0x30], 0xfffffffe
            //   41be03000000         | inc                 eax
            //   4489b590000000       | push                ebx
            //   488d55e0             | push                esi

        $sequence_8 = { eb3b 8b442444 8b8c24f8000000 2bc8 8bc1 8b4c2444 }
            // n = 6, score = 100
            //   eb3b                 | mov                 eax, dword ptr [esp + 0x78]
            //   8b442444             | dec                 eax
            //   8b8c24f8000000       | cmp                 dword ptr [esp + 0x70], eax
            //   2bc8                 | nop                 
            //   8bc1                 | dec                 eax
            //   8b4c2444             | lea                 ecx, [esp + 0x70]

        $sequence_9 = { 33c9 ff15???????? 85c0 7427 488b4c2438 488d157e2b0700 }
            // n = 6, score = 100
            //   33c9                 | inc                 edx
            //   ff15????????         |                     
            //   85c0                 | nop                 
            //   7427                 | dec                 eax
            //   488b4c2438           | lea                 edx, [esp + 0x48]
            //   488d157e2b0700       | dec                 eax

    condition:
        7 of them and filesize < 1968128
}
Download all Yara Rules