SYMBOLCOMMON_NAMEaka. SYNONYMS
win.gemcutter (Back to overview)

GEMCUTTER

Actor(s): APT 30

VTCollection    

According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key.
GEMCUTTER checks for the presence of the mutex MicrosoftGMMZJ to ensure only one copy of GEMCUTTER is executing. If the mutex doesn't exist, the malware creates it and continues execution; otherwise, the malware signals the MicrosoftGMMExit event.

References
2015-04-01 ⋅ FireEye ⋅ FireEye
APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION
BACKBEND backspace CREAMSICLE FLASHFLOOD GEMCUTTER MILKMAID Naikon NETEAGLE ORANGEADE SHIPSHAPE SPACESHIP SslMM Sys10 WinMM xsPlus APT30
Yara Rules
[TLP:WHITE] win_gemcutter_auto (20260917 | Detects win.gemcutter.)
rule win_gemcutter_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.gemcutter."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.gemcutter"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 50 ff15???????? 8d85f0fdffff 53 50 8d45f0 50 }
            // n = 7, score = 100
            //   50                   | push                eax
            //   ff15????????         |                     
            //   8d85f0fdffff         | lea                 eax, [ebp - 0x210]
            //   53                   | push                ebx
            //   50                   | push                eax
            //   8d45f0               | lea                 eax, [ebp - 0x10]
            //   50                   | push                eax

        $sequence_1 = { 53 53 ff15???????? 8d85f0fdffff 6800020000 }
            // n = 5, score = 100
            //   53                   | push                ebx
            //   53                   | push                ebx
            //   ff15????????         |                     
            //   8d85f0fdffff         | lea                 eax, [ebp - 0x210]
            //   6800020000           | push                0x200

        $sequence_2 = { e8???????? 8d85f0fdffff 56 50 e8???????? 8b35???????? }
            // n = 6, score = 100
            //   e8????????           |                     
            //   8d85f0fdffff         | lea                 eax, [ebp - 0x210]
            //   56                   | push                esi
            //   50                   | push                eax
            //   e8????????           |                     
            //   8b35????????         |                     

        $sequence_3 = { ff15???????? 8d85f0fdffff 6800020000 50 ff15???????? 8d85f0fdffff 68???????? }
            // n = 7, score = 100
            //   ff15????????         |                     
            //   8d85f0fdffff         | lea                 eax, [ebp - 0x210]
            //   6800020000           | push                0x200
            //   50                   | push                eax
            //   ff15????????         |                     
            //   8d85f0fdffff         | lea                 eax, [ebp - 0x210]
            //   68????????           |                     

        $sequence_4 = { 53 50 ffd6 8d85f0fcffff }
            // n = 4, score = 100
            //   53                   | push                ebx
            //   50                   | push                eax
            //   ffd6                 | call                esi
            //   8d85f0fcffff         | lea                 eax, [ebp - 0x310]

        $sequence_5 = { 8a08 84c9 7408 80e905 8808 40 ebf2 }
            // n = 7, score = 100
            //   8a08                 | mov                 cl, byte ptr [eax]
            //   84c9                 | test                cl, cl
            //   7408                 | je                  0xa
            //   80e905               | sub                 cl, 5
            //   8808                 | mov                 byte ptr [eax], cl
            //   40                   | inc                 eax
            //   ebf2                 | jmp                 0xfffffff4

        $sequence_6 = { 8d8500fcffff 68???????? 50 e8???????? 59 33c0 }
            // n = 6, score = 100
            //   8d8500fcffff         | lea                 eax, [ebp - 0x400]
            //   68????????           |                     
            //   50                   | push                eax
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   33c0                 | xor                 eax, eax

        $sequence_7 = { 7408 80e905 8808 40 ebf2 c3 }
            // n = 6, score = 100
            //   7408                 | je                  0xa
            //   80e905               | sub                 cl, 5
            //   8808                 | mov                 byte ptr [eax], cl
            //   40                   | inc                 eax
            //   ebf2                 | jmp                 0xfffffff4
            //   c3                   | ret                 

        $sequence_8 = { ff15???????? 83c420 8818 8d85f0fdffff 50 }
            // n = 5, score = 100
            //   ff15????????         |                     
            //   83c420               | add                 esp, 0x20
            //   8818                 | mov                 byte ptr [eax], bl
            //   8d85f0fdffff         | lea                 eax, [ebp - 0x210]
            //   50                   | push                eax

        $sequence_9 = { 8d85f0fdffff 59 50 ff15???????? 0c06 50 }
            // n = 6, score = 100
            //   8d85f0fdffff         | lea                 eax, [ebp - 0x210]
            //   59                   | pop                 ecx
            //   50                   | push                eax
            //   ff15????????         |                     
            //   0c06                 | or                  al, 6
            //   50                   | push                eax

    condition:
        7 of them and filesize < 40960
}
Download all Yara Rules