SYMBOLCOMMON_NAMEaka. SYNONYMS
win.koadic (Back to overview)

Koadic

Actor(s): APT28, Stone Panda

VTCollection    

Koadic is an open-source post-exploitation framework for Windows, created by zerosum0x0 and available on GitHub. The framework is written in Python and can generate JScript and VBScript payloads which can be written to disk or mapped directly into memory. Its capabilities include remote desktop access, command execution, lateral movement via SMB, file transfer, credential theft using Mimikatz, port scanning, and system information collection. It can also collect specific system information and targeted files based on their name or extension.

References
2024-01-25 ⋅ JSAC 2024 ⋅ Masafumi Takeda, Tomoya Furukawa
Threat Intelligence of Abused Public Post-Exploitation Frameworks
AsyncRAT DCRat Empire Downloader GRUNT Havoc Koadic Merlin PoshC2 Quasar RAT Sliver
2021-03-18 ⋅ PRODAFT Threat Intelligence ⋅ PRODAFT
SilverFish GroupThreat Actor Report
Cobalt Strike Dridex Koadic
2021-02-24 ⋅ Malwarebytes ⋅ Hossein Jazi
LazyScripter: From Empire to double RAT
Octopus Koadic
2021-01-13 ⋅ AlienVault ⋅ Tom Hegel
A Global Perspective of the SideWinder APT
8.t Dropper Koadic SideWinder
2021-01-01 ⋅ SecureWorks
Threat Profile: GOLD DRAKE
Cobalt Strike Dridex FriedEx Koadic MimiKatz WastedLocker Evil Corp
2020-11-28 ⋅ pat_h/to/file ⋅ pat_h/to/file
Hunting Koadic Pt. 2 - JARM Fingerprinting
Koadic
2020-03-20 ⋅ Bitdefender ⋅ Liviu Arsene
5 Times More Coronavirus-themed Malware Reports during March
ostap HawkEye Keylogger Koadic Loki Password Stealer (PWS) Nanocore RAT Remcos
2020-01-09 ⋅ Github (zerosum0x0) ⋅ zerosum0x0
Koadic
Koadic
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
COBALT TRINITY
POWERTON pupy Imminent Monitor RAT Koadic Nanocore RAT NetWire RC PoshC2 APT33
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
GOLD DRAKE
Dridex Empire Downloader FriedEx Koadic MimiKatz
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
COBALT ULSTER
POWERSTATS Koadic MuddyWater
2018-06-06 ⋅ Palo Alto Networks Unit 42 ⋅ Bryan Lee, Robert Falcone
Sofacy Group’s Parallel Attacks
Koadic Zebrocy
Yara Rules
[TLP:WHITE] win_koadic_auto (20260917 | Detects win.koadic.)
rule win_koadic_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.koadic."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.koadic"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8a08 40 84c9 75f9 2bc2 b940000000 2bc8 }
            // n = 7, score = 100
            //   8a08                 | mov                 cl, byte ptr [eax]
            //   40                   | inc                 eax
            //   84c9                 | test                cl, cl
            //   75f9                 | jne                 0xfffffffb
            //   2bc2                 | sub                 eax, edx
            //   b940000000           | mov                 ecx, 0x40
            //   2bc8                 | sub                 ecx, eax

        $sequence_1 = { 7510 84db 7420 ff4c2414 741a 8b44241c ebd4 }
            // n = 7, score = 100
            //   7510                 | jne                 0x12
            //   84db                 | test                bl, bl
            //   7420                 | je                  0x22
            //   ff4c2414             | dec                 dword ptr [esp + 0x14]
            //   741a                 | je                  0x1c
            //   8b44241c             | mov                 eax, dword ptr [esp + 0x1c]
            //   ebd4                 | jmp                 0xffffffd6

        $sequence_2 = { ff742404 8b5c240c 83c320 53 e8???????? ff35???????? ff35???????? }
            // n = 7, score = 100
            //   ff742404             | push                dword ptr [esp + 4]
            //   8b5c240c             | mov                 ebx, dword ptr [esp + 0xc]
            //   83c320               | add                 ebx, 0x20
            //   53                   | push                ebx
            //   e8????????           |                     
            //   ff35????????         |                     
            //   ff35????????         |                     

        $sequence_3 = { 85f6 7472 668b2c19 663b2c1a 7f1a 8908 8b4c2410 }
            // n = 7, score = 100
            //   85f6                 | test                esi, esi
            //   7472                 | je                  0x74
            //   668b2c19             | mov                 bp, word ptr [ecx + ebx]
            //   663b2c1a             | cmp                 bp, word ptr [edx + ebx]
            //   7f1a                 | jg                  0x1c
            //   8908                 | mov                 dword ptr [eax], ecx
            //   8b4c2410             | mov                 ecx, dword ptr [esp + 0x10]

        $sequence_4 = { 5e 5b 5d c21c00 33c0 50 }
            // n = 6, score = 100
            //   5e                   | pop                 esi
            //   5b                   | pop                 ebx
            //   5d                   | pop                 ebp
            //   c21c00               | ret                 0x1c
            //   33c0                 | xor                 eax, eax
            //   50                   | push                eax

        $sequence_5 = { 83ec14 53 55 56 8b742428 8a06 }
            // n = 6, score = 100
            //   83ec14               | sub                 esp, 0x14
            //   53                   | push                ebx
            //   55                   | push                ebp
            //   56                   | push                esi
            //   8b742428             | mov                 esi, dword ptr [esp + 0x28]
            //   8a06                 | mov                 al, byte ptr [esi]

        $sequence_6 = { 8b4c2410 89542428 4e 85ff 75be 85f6 7416 }
            // n = 7, score = 100
            //   8b4c2410             | mov                 ecx, dword ptr [esp + 0x10]
            //   89542428             | mov                 dword ptr [esp + 0x28], edx
            //   4e                   | dec                 esi
            //   85ff                 | test                edi, edi
            //   75be                 | jne                 0xffffffc0
            //   85f6                 | test                esi, esi
            //   7416                 | je                  0x18

        $sequence_7 = { e8???????? 395d0c 7437 ff7510 }
            // n = 4, score = 100
            //   e8????????           |                     
            //   395d0c               | cmp                 dword ptr [ebp + 0xc], ebx
            //   7437                 | je                  0x39
            //   ff7510               | push                dword ptr [ebp + 0x10]

        $sequence_8 = { 85c0 740b 8bff 48 8b09 894c2424 75f7 }
            // n = 7, score = 100
            //   85c0                 | test                eax, eax
            //   740b                 | je                  0xd
            //   8bff                 | mov                 edi, edi
            //   48                   | dec                 eax
            //   8b09                 | mov                 ecx, dword ptr [ecx]
            //   894c2424             | mov                 dword ptr [esp + 0x24], ecx
            //   75f7                 | jne                 0xfffffff9

        $sequence_9 = { e9???????? 8b442408 56 8b30 8b46f8 83ee18 57 }
            // n = 7, score = 100
            //   e9????????           |                     
            //   8b442408             | mov                 eax, dword ptr [esp + 8]
            //   56                   | push                esi
            //   8b30                 | mov                 esi, dword ptr [eax]
            //   8b46f8               | mov                 eax, dword ptr [esi - 8]
            //   83ee18               | sub                 esi, 0x18
            //   57                   | push                edi

    condition:
        7 of them and filesize < 180224
}
Download all Yara Rules