SYMBOLCOMMON_NAMEaka. SYNONYMS
win.devilstongue (Back to overview)

DevilsTongue

Actor(s): Caramel Tsunami

VTCollection    

According to Microsoft, DevilsTongue is a complex modular multi-threaded piece of malware written in C and C++ with several novel capabilities.
For files on disk, PDB paths and PE timestamps are scrubbed, strings and configs are encrypted, and each file has a unique hash. The main functionality resides in DLLs that are encrypted on disk and only decrypted in memory, making detection more difficult. Configuration and tasking data is separate from the malware, which makes analysis harder. DevilsTongue has both user mode and kernel mode capabilities.

References
2021-07-15 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Protecting customers from a private-sector offensive actor using 0-day exploits and DevilsTongue malware
DevilsTongue Caramel Tsunami
Yara Rules
[TLP:WHITE] win_devilstongue_auto (20260917 | Detects win.devilstongue.)
rule win_devilstongue_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.devilstongue."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.devilstongue"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4d85c0 0f94442402 bba2984e80 ebc5 81fb97ab74c9 0f8f97000000 81fba2984e80 }
            // n = 7, score = 100
            //   4d85c0               | dec                 esp
            //   0f94442402           | mov                 esi, ecx
            //   bba2984e80           | dec                 ecx
            //   ebc5                 | mov                 edi, edx
            //   81fb97ab74c9         | dec                 eax
            //   0f8f97000000         | cmp                 dword ptr [ecx], 0
            //   81fba2984e80         | je                  0xb24

        $sequence_1 = { 4883ec28 4889d1 e8???????? b801000000 4883c428 c3 56 }
            // n = 7, score = 100
            //   4883ec28             | push                ebx
            //   4889d1               | dec                 eax
            //   e8????????           |                     
            //   b801000000           | sub                 esp, 0x28
            //   4883c428             | dec                 eax
            //   c3                   | lea                 ebp, [edx + 0x60]
            //   56                   | dec                 eax

        $sequence_2 = { 4829d7 48bdffffffffffffff7f 4889e9 4829f9 4839cb 0f879b010000 4d89fe }
            // n = 7, score = 100
            //   4829d7               | inc                 esp
            //   48bdffffffffffffff7f     | jne    0xfffffff6
            //   4889e9               | jmp                 0xd
            //   4829f9               | mov                 eax, 0x445c91b1
            //   4839cb               | jmp                 0xfffffff6
            //   0f879b010000         | dec                 eax
            //   4d89fe               | mov                 dword ptr [esp + 8], ecx

        $sequence_3 = { 4c89e1 e8???????? 4829d8 4839e8 0f82dc010000 4801dd 4c8b6f18 }
            // n = 7, score = 100
            //   4c89e1               | dec                 eax
            //   e8????????           |                     
            //   4829d8               | lea                 ecx, [esi + 0x10]
            //   4839e8               | inc                 ebp
            //   0f82dc010000         | mov                 eax, dword ptr [eax]
            //   4801dd               | dec                 eax
            //   4c8b6f18             | mov                 eax, esi

        $sequence_4 = { 85c0 0f8492010000 e9???????? 488b442448 49894608 8b442450 41894618 }
            // n = 7, score = 100
            //   85c0                 | mov                 ecx, dword ptr [esp]
            //   0f8492010000         | mov                 ecx, 0x50ecbd49
            //   e9????????           |                     
            //   488b442448           | dec                 ecx
            //   49894608             | mov                 ecx, edx
            //   8b442450             | jmp                 0x688
            //   41894618             | dec                 esp

        $sequence_5 = { 48895818 48897020 488b05???????? 4833c4 488985f0010000 418bf0 4c8bf2 }
            // n = 7, score = 100
            //   48895818             | mov                 ecx, dword ptr [esp + 0x20]
            //   48897020             | dec                 eax
            //   488b05????????       |                     
            //   4833c4               | mov                 edx, edi
            //   488985f0010000       | dec                 ecx
            //   418bf0               | mov                 eax, ebx
            //   4c8bf2               | dec                 eax

        $sequence_6 = { 57 4883ec30 488d6c2430 48c745f8feffffff 4889d6 4889cf 4c89c2 }
            // n = 7, score = 100
            //   57                   | dec                 ecx
            //   4883ec30             | sub                 ebp, esi
            //   488d6c2430           | mov                 eax, 0xcde3b609
            //   48c745f8feffffff     | dec                 esp
            //   4889d6               | lea                 esp, [ebp - 0x38]
            //   4889cf               | cmp                 eax, 0xaaa31545
            //   4c89c2               | je                  0xeee

        $sequence_7 = { 488d4d08 41b80c000000 e8???????? 488d4d08 e8???????? 488d4dc8 4889c2 }
            // n = 7, score = 100
            //   488d4d08             | jmp                 0x1435
            //   41b80c000000         | dec                 eax
            //   e8????????           |                     
            //   488d4d08             | mov                 dword ptr [esp + 0x20], edi
            //   e8????????           |                     
            //   488d4dc8             | dec                 eax
            //   4889c2               | mov                 ecx, dword ptr [esp + 0x20]

        $sequence_8 = { 488b442428 488b442420 488b442438 b800554687 e9???????? 488b4c2470 4831e1 }
            // n = 7, score = 100
            //   488b442428           | inc                 ecx
            //   488b442420           | mov                 ecx, ebp
            //   488b442438           | dec                 eax
            //   b800554687           | mov                 dword ptr [esp + 0x38], eax
            //   e9????????           |                     
            //   488b4c2470           | mov                 eax, 0x886bf338
            //   4831e1               | jmp                 0x9b7

        $sequence_9 = { 81fa15b7785c 75f0 488b542410 48c7411000000000 ba251f32f5 ebdc }
            // n = 6, score = 100
            //   81fa15b7785c         | jne                 0x1a7
            //   75f0                 | dec                 esp
            //   488b542410           | mov                 ecx, edi
            //   48c7411000000000     | jg                  0x136
            //   ba251f32f5           | cmp                 eax, 0x45b54eab
            //   ebdc                 | je                  0x19e

    condition:
        7 of them and filesize < 990208
}
Download all Yara Rules