SYMBOLCOMMON_NAMEaka. SYNONYMS
win.dpapi_loader (Back to overview)

DPAPILoader

Actor(s): Lazarus Group

VTCollection    

According to Fox-IT, DPAPILoader is a loader implemented as a DLL that decrypts an encrypted payload from disk using DPAPI and then loads it into memory, enabling persistence by starting at boot as a legitimate-appearing service. It uses environment-bound encryption and obfuscation (DPAPI keys tied to the user and a fixed XOR) to tie the payload to the victim and hinder static analysis. The loader then hands off to a second-stage loader, RemotePELoader, as part of a multi-stage chain designed to minimize on-disk artifacts and maximize stealth.

References
2026-05-22 ⋅ Fox-IT ⋅ Mick Koomen, Yun Zheng Hu
RemotePE: The Lazarus RAT that lives in memory
DPAPILoader RemotePE
Yara Rules
[TLP:WHITE] win_dpapi_loader_auto (20260917 | Detects win.dpapi_loader.)
rule win_dpapi_loader_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.dpapi_loader."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dpapi_loader"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488b00 ff15???????? e9???????? 48833a00 7c69 7506 837a0800 }
            // n = 7, score = 100
            //   488b00               | dec                 eax
            //   ff15????????         |                     
            //   e9????????           |                     
            //   48833a00             | lea                 ecx, [ebx + 8]
            //   7c69                 | dec                 eax
            //   7506                 | mov                 dword ptr [ebx], eax
            //   837a0800             | xor                 eax, eax

        $sequence_1 = { 4c8bc3 488d15a04e0400 e8???????? 85c0 744c 4883fe10 488d4c2428 }
            // n = 7, score = 100
            //   4c8bc3               | dec                 eax
            //   488d15a04e0400       | lea                 ecx, [ebp + 0x27]
            //   e8????????           |                     
            //   85c0                 | dec                 eax
            //   744c                 | mov                 eax, dword ptr [edx]
            //   4883fe10             | dec                 eax
            //   488d4c2428           | mov                 dword ptr [esp + 0x30], ecx

        $sequence_2 = { 4c8d4710 488d4b10 493bc8 7416 498bd0 4983781810 7203 }
            // n = 7, score = 100
            //   4c8d4710             | nop                 
            //   488d4b10             | cmp                 eax, 0x20
            //   493bc8               | jne                 0x876
            //   7416                 | xorps               xmm0, xmm0
            //   498bd0               | dec                 eax
            //   4983781810           | mov                 ecx, dword ptr [ebp - 0x29]
            //   7203                 | nop                 

        $sequence_3 = { 0fb683a0010000 418886a0010000 488daba8010000 483bf5 7415 488b06 488bce }
            // n = 7, score = 100
            //   0fb683a0010000       | dec                 eax
            //   418886a0010000       | arpl                word ptr [eax + 4], cx
            //   488daba8010000       | test                ebx, ebx
            //   483bf5               | jle                 0x208
            //   7415                 | dec                 ecx
            //   488b06               | dec                 ecx
            //   488bce               | dec                 ecx

        $sequence_4 = { 48897c2458 4c8d442438 488d542460 488d4d60 e8???????? 90 488d4c2438 }
            // n = 7, score = 100
            //   48897c2458           | test                al, al
            //   4c8d442438           | jne                 0x6a1
            //   488d542460           | dec                 ecx
            //   488d4d60             | mov                 ecx, esp
            //   e8????????           |                     
            //   90                   | and                 ebx, dword ptr [eax + 0x14]
            //   488d4c2438           | jne                 0x79e

        $sequence_5 = { d3e8 4189411c 410fb608 83e10f 4a0fbe8419c07b0400 }
            // n = 5, score = 100
            //   d3e8                 | dec                 ecx
            //   4189411c             | lea                 ecx, [edi + 0x10]
            //   410fb608             | dec                 ecx
            //   83e10f               | cmp                 dword ptr [edi + 0x28], 0x10
            //   4a0fbe8419c07b0400     | jb    0x19c

        $sequence_6 = { e8???????? 498b07 4d8bc6 488bd6 498bcf ff5070 498bb788010000 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   498b07               | mov                 ecx, esp
            //   4d8bc6               | dec                 eax
            //   488bd6               | mov                 eax, ebx
            //   498bcf               | dec                 eax
            //   ff5070               | mov                 ecx, dword ptr [ebp - 1]
            //   498bb788010000       | dec                 eax

        $sequence_7 = { 488d1dd0a80400 eb15 f6c202 488d1ddca80400 488d05eda80400 480f44d8 }
            // n = 6, score = 100
            //   488d1dd0a80400       | cmp                 eax, 0x1f
            //   eb15                 | ja                  0x1088
            //   f6c202               | dec                 esp
            //   488d1ddca80400       | mov                 esi, dword ptr [esp + 0x70]
            //   488d05eda80400       | inc                 ecx
            //   480f44d8             | test                byte ptr [esp + 0x70], 2

        $sequence_8 = { 0f114718 0f104e18 0f114f28 48894618 48c746200f000000 884608 488b4d10 }
            // n = 7, score = 100
            //   0f114718             | dec                 eax
            //   0f104e18             | mov                 edx, dword ptr [ebp - 9]
            //   0f114f28             | dec                 eax
            //   48894618             | cmp                 edx, 0x10
            //   48c746200f000000     | jne                 0x417
            //   884608               | movaps              xmm0, xmmword ptr [ebp - 0x71]
            //   488b4d10             | dec                 eax

        $sequence_9 = { 8b4f10 3b4810 7411 488bd8 483bc2 744a }
            // n = 6, score = 100
            //   8b4f10               | dec                 ecx
            //   3b4810               | cmp                 esi, 0x16
            //   7411                 | dec                 ecx
            //   488bd8               | or                  esi, 0xffffffff
            //   483bc2               | xor                 ebx, ebx
            //   744a                 | dec                 esp

    condition:
        7 of them and filesize < 855040
}
Download all Yara Rules