Actor(s): APT29
This loader abuses the benign service Notion for data exchange.
rule win_graphical_neutrino_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.graphical_neutrino." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphical_neutrino" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 4889c1 4889442468 48c744247801000000 e8???????? 488d8c24f0010000 4c89fa } // n = 6, score = 500 // 4889c1 | dec eax // 4889442468 | lea edi, [esp + 0x60] // 48c744247801000000 | dec eax // e8???????? | // 488d8c24f0010000 | lea esi, [0x31739] // 4c89fa | rep movsb byte ptr es:[edi], byte ptr [esi] $sequence_1 = { 4c89442430 e8???????? 488b442440 488b6c2448 4889442428 29ee 791a } // n = 7, score = 500 // 4c89442430 | cmp esi, 0xd // e8???????? | // 488b442440 | ja 0x5cf // 488b6c2448 | cmp esi, 7 // 4889442428 | jbe 0xf4 // 29ee | lea eax, [esi - 8] // 791a | je 0xa0 $sequence_2 = { f3aa 498d442c02 4801d8 eb2f 488d5301 } // n = 5, score = 500 // f3aa | mov esi, ecx // 498d442c02 | dec eax // 4801d8 | lea edi, [esp + 0xb0] // eb2f | push ebx // 488d5301 | dec eax $sequence_3 = { 4c89e9 488b742460 4c8d842480000000 e8???????? 488b442460 } // n = 5, score = 500 // 4c89e9 | stosb byte ptr es:[edi], al // 488b742460 | stosb byte ptr es:[edi], al // 4c8d842480000000 | stosb byte ptr es:[edi], al // e8???????? | // 488b442460 | stosb byte ptr es:[edi], al $sequence_4 = { 8d5001 8913 45882c04 486b4424400a 4889442440 } // n = 5, score = 500 // 8d5001 | dec esp // 8913 | mov edx, ebp // 45882c04 | dec esp // 486b4424400a | mov ecx, esp // 4889442440 | dec ecx $sequence_5 = { 89f8 89c2 ffc8 4885f6 7805 4801f6 } // n = 6, score = 500 // 89f8 | test eax, eax // 89c2 | je 0x12d1 // ffc8 | dec esp // 4885f6 | mov edx, ebp // 7805 | dec eax // 4801f6 | lea ecx, [0x3e646] $sequence_6 = { 4c89fa 498d4940 e8???????? 4c8b442428 4c89f2 4889f9 e8???????? } // n = 7, score = 500 // 4c89fa | cmp eax, 0x7f // 498d4940 | inc ecx // e8???????? | // 4c8b442428 | push esp // 4c89f2 | push esi // 4889f9 | push ebx // e8???????? | $sequence_7 = { 8b6c242c 48637c2428 8d743d00 39f7 7f2b 83fe0f 7f26 } // n = 7, score = 500 // 8b6c242c | dec esp // 48637c2428 | mov edx, edi // 8d743d00 | dec eax // 39f7 | mov eax, dword ptr [esp + 0x40] // 7f2b | dec eax // 83fe0f | mov ecx, dword ptr [esp + 0x38] // 7f26 | dec esp $sequence_8 = { 4c89e9 e8???????? 4c89e1 4c89f2 4c8d4010 e8???????? } // n = 6, score = 500 // 4c89e9 | lea edx, [0x3bf8e] // e8???????? | // 4c89e1 | dec ecx // 4c89f2 | mov eax, edx // 4c8d4010 | cmp ecx, eax // e8???????? | $sequence_9 = { 4c8da424c0000000 48c78424c800000002000000 48898424a0000000 4c89e2 48898424c0000000 488d8424e8040000 4889c1 } // n = 7, score = 500 // 4c8da424c0000000 | lea ebx, [esp + 0x68] // 48c78424c800000002000000 | dec esp // 48898424a0000000 | mov edx, ebp // 4c89e2 | dec esp // 48898424c0000000 | mov ecx, esp // 488d8424e8040000 | inc ecx // 4889c1 | mov eax, 0x103 condition: 7 of them and filesize < 674816 }
rule win_graphical_neutrino_w0 { meta: author = "Military Counterlintelligence Service and CERT.PL" date = "2023-04-13" description = "Detects win.graphical_neutrino." source = "https://www.gov.pl/attachment/ee91f24d-3e67-436d-aa50-7fa56acf789d" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.graphical_neutrino" malpedia_rule_date = "20230601" malpedia_hash = "" malpedia_version = "20230601" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" strings: // Payload decryption loop // Custom algorithm based on XOR $op_decrypt_payload = {49 8B 45 08 48 ?? ?? ?? 48 39 ?? 76 2B 48 89 C8 31 D2 4C 8B 4C 24 ?? 48 F7 74 24 ?? 49 8B 45 00 41 8A 14 11 32 54 08 10 89 C8 41 0F AF C0 31 C2 88 14 0B 48 FF C1} // Decryption routine generated by Obfuscate library $op_decrypt_string = {48 39 D0 74 19 48 89 C1 4D 89 C2 83 E1 07 48 C1 E1 03 49 D3 EA 45 30 14 01 48 FF C0 EB E2} // Hardcoded inital value used as beaconing counter $op_initialize_emoji = {C6 [3] A5 66 [4] F0 9F} // src/json.hpp - string left in binary using nlohmann JSON $str_nlohmann = {73 72 63 2F 6A 73 6F 6E 2E 68 70 70 00} condition: uint16(0) == 0x5A4D and filesize < 500KB and $str_nlohmann and $op_decrypt_string and ($op_initialize_emoji or $op_decrypt_payload) }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY