SYMBOLCOMMON_NAMEaka. SYNONYMS
win.banpolmex (Back to overview)

BanPolMex RAT

Actor(s): Lazarus Group

VTCollection    

BanPolMex is a remote access trojan that uses TCP for communication.

It uses an RC4-like stream cipher called Spritz for encryption of its configuration and network traffic.

It sends detailed information about the victim's environment, like computer name, Windows version, free space of memory and all drives, processor identifier and architecture, system locale, system metrics, manufacturer, and network configuration.

It supports almost 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration, and the download and execution of additional tools from the attacker’s C&C server. As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. However, in this case the indicis are convertible into a meaningful ASCII representation, that even suggests the functionality: SLEP, HIBN, DRIV, DIR, DIRP, CHDR, RUN, RUNX, DEL, WIPE, MOVE, FTIM, NEWF, DOWN, ZDWN, UPLD, PVEW, PKIL, CMDL, DIE, GCFG, SCFG, TCON, PEEX, PEIN.

It has aclui.dll as the internal DLL name. It contains statically linked code from open-source libraries like libcurl (version 7.47.1) or zLib (version 0.15).

BanPolMex RAT was delivered for victims of a watering hole campaign targeting employees of Polish and Mexican banks, that was discovered in February 2017. It is usually loaded by HOTWAX.

References
2018-10-03 ⋅ Virus Bulletin ⋅ Michal Poslušný, Peter Kálnai
Lazarus Group A Mahjong Game Played with Different Sets of Tiles
Bankshot BanPolMex RAT FuwuqiDrama HOTWAX KillDisk (Lazarus) NACHOCHEESE REDSHAWL WannaCryptor
2017-02-16 ⋅ ESET Research ⋅ Peter Kálnai
Demystifying targeted malware used against Polish banks
BanPolMex RAT HOTWAX NACHOCHEESE
Yara Rules
[TLP:WHITE] win_banpolmex_auto (20260917 | Detects win.banpolmex.)
rule win_banpolmex_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.banpolmex."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.banpolmex"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4c8d5170 0fb78168030000 4c8d8962020000 498bd3 c1e804 498bca 83e001 }
            // n = 7, score = 100
            //   4c8d5170             | dec                 eax
            //   0fb78168030000       | lea                 ecx, [0x1a1af]
            //   4c8d8962020000       | dec                 esp
            //   498bd3               | mov                 esp, eax
            //   c1e804               | dec                 eax
            //   498bca               | test                eax, eax
            //   83e001               | jne                 0x1fa3

        $sequence_1 = { eb03 448bed 488b5108 4885d2 750e b88dfeffff 4883c440 }
            // n = 7, score = 100
            //   eb03                 | inc                 esp
            //   448bed               | mov                 ebx, eax
            //   488b5108             | test                eax, eax
            //   4885d2               | jne                 0x1939
            //   750e                 | dec                 eax
            //   b88dfeffff           | lea                 edx, [esp + 0x40]
            //   4883c440             | dec                 eax

        $sequence_2 = { 488d1d8c8f0700 488bcb 33d2 41b8c8180000 e8???????? }
            // n = 5, score = 100
            //   488d1d8c8f0700       | inc                 ecx
            //   488bcb               | cmp                 ebp, 1
            //   33d2                 | je                  0x126c
            //   41b8c8180000         | dec                 eax
            //   e8????????           |                     

        $sequence_3 = { ff15???????? 4c8d0592340800 488d4c2420 4c8bcf baff030000 e8???????? 488d157d340800 }
            // n = 7, score = 100
            //   ff15????????         |                     
            //   4c8d0592340800       | ret                 
            //   488d4c2420           | dec                 esp
            //   4c8bcf               | lea                 ecx, [0x71eb1]
            //   baff030000           | dec                 eax
            //   e8????????           |                     
            //   488d157d340800       | add                 ecx, edx

        $sequence_4 = { 4803ff 4c8d2da50e0600 49837cfd0000 7404 8bc6 eb79 b928000000 }
            // n = 7, score = 100
            //   4803ff               | mov                 ecx, edi
            //   4c8d2da50e0600       | inc                 esp
            //   49837cfd0000         | mov                 ebp, eax
            //   7404                 | dec                 esp
            //   8bc6                 | lea                 ecx, [esi + 0xc0]
            //   eb79                 | dec                 eax
            //   b928000000           | lea                 edx, [esi + 0x80]

        $sequence_5 = { e8???????? 85c0 752e 418bff eb29 }
            // n = 5, score = 100
            //   e8????????           |                     
            //   85c0                 | test                eax, eax
            //   752e                 | je                  0x6c0
            //   418bff               | mov                 eax, 0xffffff96
            //   eb29                 | dec                 eax

        $sequence_6 = { 740d f6876a03000010 0f848e000000 41b802000000 410fb6d3 410fb6ca e8???????? }
            // n = 7, score = 100
            //   740d                 | lea                 edx, [0x898c5]
            //   f6876a03000010       | dec                 eax
            //   0f848e000000         | lea                 edx, [0x897d1]
            //   41b802000000         | dec                 eax
            //   410fb6d3             | mov                 ecx, ebx
            //   410fb6ca             | dec                 eax
            //   e8????????           |                     

        $sequence_7 = { 488d159ad10700 488d4c2430 448bc6 e8???????? 488d55b7 488d4c2430 41b808000000 }
            // n = 7, score = 100
            //   488d159ad10700       | lea                 ecx, [ebx + 0xf88]
            //   488d4c2430           | mov                 dword ptr [ecx], 0x40
            //   448bc6               | dec                 eax
            //   e8????????           |                     
            //   488d55b7             | lea                 edx, [ebx + 0xfd0]
            //   488d4c2430           | dec                 eax
            //   41b808000000         | lea                 ecx, [ebx + 0xfc8]

        $sequence_8 = { 44896500 85c0 7f19 488d15f2a90200 488bce e8???????? }
            // n = 6, score = 100
            //   44896500             | jne                 0x529
            //   85c0                 | xor                 eax, eax
            //   7f19                 | jmp                 0x548
            //   488d15f2a90200       | mov                 eax, edi
            //   488bce               | test                dx, cx
            //   e8????????           |                     

        $sequence_9 = { 6689442455 88442457 33db e8???????? 4885c0 7417 488d15f0a40300 }
            // n = 7, score = 100
            //   6689442455           | dec                 esp
            //   88442457             | mov                 edi, ebx
            //   33db                 | dec                 esp
            //   e8????????           |                     
            //   4885c0               | mov                 esp, ebx
            //   7417                 | dec                 eax
            //   488d15f0a40300       | lea                 eax, [0x6fa22]

    condition:
        7 of them and filesize < 1555456
}
Download all Yara Rules