SYMBOLCOMMON_NAMEaka. SYNONYMS
win.graphical_neutrino (Back to overview)

GraphicalNeutrino

aka: SNOWYAMBER

Actor(s): APT29

VTCollection    

This loader abuses the benign service Notion for data exchange.

References
2023-07-27 ⋅ Recorded Future ⋅ Insikt Group
BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware
GraphDrop GraphicalNeutrino QUARTERRIG
2023-06-02 ⋅ MSSP Lab ⋅ cocomelonc
Malware analysis report: SNOWYAMBER (+APT29 related malwares)
GraphicalNeutrino
2023-04-13 ⋅ GOV.PL ⋅ CERT.PL, Military Counterintelligence Service
SNOWYAMBER - Malware Analysis Report
GraphicalNeutrino
2023-03-14 ⋅ Blackberry ⋅ BlackBerry Research & Intelligence Team
NOBELIUM Uses Poland's Ambassador’s Visit to the U.S. to Target EU Governments Assisting Ukraine
EnvyScout GraphicalNeutrino
2023-03-10 ⋅ Mrtiepolo ⋅ Gianluca Tiepolo
Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
BEATDROP EnvyScout GraphicalNeutrino tDiscoverer VaporRage
2023-01-26 ⋅ Recorded Future ⋅ Insikt Group
BlueBravo Uses Ambassador Lure to Deploy GraphicalNeutrino Malware
GraphicalNeutrino APT29
Yara Rules
[TLP:WHITE] win_graphical_neutrino_auto (20260917 | Detects win.graphical_neutrino.)
rule win_graphical_neutrino_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.graphical_neutrino."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphical_neutrino"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4889c1 4889442468 48c744247801000000 e8???????? 488d8c24f0010000 4c89fa }
            // n = 6, score = 500
            //   4889c1               | dec                 eax
            //   4889442468           | lea                 edi, [esp + 0x60]
            //   48c744247801000000     | dec    eax
            //   e8????????           |                     
            //   488d8c24f0010000     | lea                 esi, [0x31739]
            //   4c89fa               | rep movsb           byte ptr es:[edi], byte ptr [esi]

        $sequence_1 = { 4c89442430 e8???????? 488b442440 488b6c2448 4889442428 29ee 791a }
            // n = 7, score = 500
            //   4c89442430           | cmp                 esi, 0xd
            //   e8????????           |                     
            //   488b442440           | ja                  0x5cf
            //   488b6c2448           | cmp                 esi, 7
            //   4889442428           | jbe                 0xf4
            //   29ee                 | lea                 eax, [esi - 8]
            //   791a                 | je                  0xa0

        $sequence_2 = { f3aa 498d442c02 4801d8 eb2f 488d5301 }
            // n = 5, score = 500
            //   f3aa                 | mov                 esi, ecx
            //   498d442c02           | dec                 eax
            //   4801d8               | lea                 edi, [esp + 0xb0]
            //   eb2f                 | push                ebx
            //   488d5301             | dec                 eax

        $sequence_3 = { 4c89e9 488b742460 4c8d842480000000 e8???????? 488b442460 }
            // n = 5, score = 500
            //   4c89e9               | stosb               byte ptr es:[edi], al
            //   488b742460           | stosb               byte ptr es:[edi], al
            //   4c8d842480000000     | stosb               byte ptr es:[edi], al
            //   e8????????           |                     
            //   488b442460           | stosb               byte ptr es:[edi], al

        $sequence_4 = { 8d5001 8913 45882c04 486b4424400a 4889442440 }
            // n = 5, score = 500
            //   8d5001               | dec                 esp
            //   8913                 | mov                 edx, ebp
            //   45882c04             | dec                 esp
            //   486b4424400a         | mov                 ecx, esp
            //   4889442440           | dec                 ecx

        $sequence_5 = { 89f8 89c2 ffc8 4885f6 7805 4801f6 }
            // n = 6, score = 500
            //   89f8                 | test                eax, eax
            //   89c2                 | je                  0x12d1
            //   ffc8                 | dec                 esp
            //   4885f6               | mov                 edx, ebp
            //   7805                 | dec                 eax
            //   4801f6               | lea                 ecx, [0x3e646]

        $sequence_6 = { 4c89fa 498d4940 e8???????? 4c8b442428 4c89f2 4889f9 e8???????? }
            // n = 7, score = 500
            //   4c89fa               | cmp                 eax, 0x7f
            //   498d4940             | inc                 ecx
            //   e8????????           |                     
            //   4c8b442428           | push                esp
            //   4c89f2               | push                esi
            //   4889f9               | push                ebx
            //   e8????????           |                     

        $sequence_7 = { 8b6c242c 48637c2428 8d743d00 39f7 7f2b 83fe0f 7f26 }
            // n = 7, score = 500
            //   8b6c242c             | dec                 esp
            //   48637c2428           | mov                 edx, edi
            //   8d743d00             | dec                 eax
            //   39f7                 | mov                 eax, dword ptr [esp + 0x40]
            //   7f2b                 | dec                 eax
            //   83fe0f               | mov                 ecx, dword ptr [esp + 0x38]
            //   7f26                 | dec                 esp

        $sequence_8 = { 4c89e9 e8???????? 4c89e1 4c89f2 4c8d4010 e8???????? }
            // n = 6, score = 500
            //   4c89e9               | lea                 edx, [0x3bf8e]
            //   e8????????           |                     
            //   4c89e1               | dec                 ecx
            //   4c89f2               | mov                 eax, edx
            //   4c8d4010             | cmp                 ecx, eax
            //   e8????????           |                     

        $sequence_9 = { 4c8da424c0000000 48c78424c800000002000000 48898424a0000000 4c89e2 48898424c0000000 488d8424e8040000 4889c1 }
            // n = 7, score = 500
            //   4c8da424c0000000     | lea                 ebx, [esp + 0x68]
            //   48c78424c800000002000000     | dec    esp
            //   48898424a0000000     | mov                 edx, ebp
            //   4c89e2               | dec                 esp
            //   48898424c0000000     | mov                 ecx, esp
            //   488d8424e8040000     | inc                 ecx
            //   4889c1               | mov                 eax, 0x103

    condition:
        7 of them and filesize < 674816
}
[TLP:WHITE] win_graphical_neutrino_w0   (20230601 | Detects win.graphical_neutrino.)
rule win_graphical_neutrino_w0 {

    meta:
        author = "Military Counterlintelligence Service and CERT.PL"
        date = "2023-04-13"
        description = "Detects win.graphical_neutrino."
        source = "https://www.gov.pl/attachment/ee91f24d-3e67-436d-aa50-7fa56acf789d"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphical_neutrino"
        malpedia_rule_date = "20230601"
        malpedia_hash = ""
        malpedia_version = "20230601"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        // Payload decryption loop
        // Custom algorithm based on XOR
        $op_decrypt_payload = {49 8B 45 08 48 ?? ?? ?? 48 39 ?? 76 2B 48 89 C8 31 D2 4C 8B 4C 24 ?? 48 F7 74 24 ?? 49 8B 45
        00 41 8A 14 11 32 54 08 10 89 C8 41 0F AF C0 31 C2 88 14 0B 48 FF C1}
        // Decryption routine generated by Obfuscate library
        $op_decrypt_string = {48 39 D0 74 19 48 89 C1 4D 89 C2 83 E1 07 48 C1 E1 03 49 D3 EA 45 30 14 01 48 FF C0 EB E2}
        // Hardcoded inital value used as beaconing counter
        $op_initialize_emoji = {C6 [3] A5 66 [4] F0 9F}
        // src/json.hpp - string left in binary using nlohmann JSON
        $str_nlohmann = {73 72 63 2F 6A 73 6F 6E 2E 68 70 70 00}
    condition:
        uint16(0) == 0x5A4D
        and
         filesize < 500KB
        and
         $str_nlohmann
        and
         $op_decrypt_string
        and
         ($op_initialize_emoji or $op_decrypt_payload)
}
Download all Yara Rules