SYMBOLCOMMON_NAMEaka. SYNONYMS
win.lightlesscan (Back to overview)

LightlessCan

aka: SIDESHOW

Actor(s): Lazarus Group

VTCollection    

LightlessCan is a complex HTTP(S) RAT, that is a successor of the Lazarus RAT named BlindingCan.

In Q2 2022 and Q1 2023, it was deployed in targeted attacks against an aerospace company in Spain and a technology company in India.

Besides the support for commands already present in BlindingCan, its most significant update is mimicked functionality of many native Windows commands:
• ipconfig
• net
• netsh advfirewall firewall
• netstat
• reg
• sc
• ping (for both IPv4 and IPv6 protocols)
• wmic process call create
• nslookup
• schstasks
• systeminfo
• arp

These native commands are often abused by the attackers after they have gotten a foothold in the target’s system. Lightless is able to execute them discreetly within the RAT itself, rather than being executed visibly in the system console. This provides stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools.

LightlessCan use RC6 for decryption of its configuration, and also for encryption and decryption of network traffic.

References
2026-09-18 ⋅ SentinelOne ⋅ Albert Priego, Alex Delamotte, Matěj Havránek
Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
Gaslight LightlessCan
2023-10-04 ⋅ Virus Bulletin ⋅ Peter Kálnai
Lazarus Campaigns and Backdoors in 2022-23
SimpleTea POOLRAT 3CX Backdoor BLINDINGCAN CLOUDBURST DRATzarus ForestTiger ImprudentCook LambLoad LightlessCan miniBlindingCan PostNapTea SecondHandTea SnatchCrypto wAgentTea WebbyTea WinInetLoader
2023-09-29 ⋅ ESET Research ⋅ Peter Kálnai
Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
CLOUDBURST LightlessCan miniBlindingCan sRDI
Yara Rules
[TLP:WHITE] win_lightlesscan_auto (20260917 | Detects win.lightlesscan.)
rule win_lightlesscan_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.lightlesscan."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lightlesscan"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 85c0 7435 66837b023a 752e 4c8d0586be0500 eb2c }
            // n = 7, score = 100
            //   e8????????           |                     
            //   85c0                 | call                eax
            //   7435                 | dec                 eax
            //   66837b023a           | mov                 ebx, eax
            //   752e                 | dec                 eax
            //   4c8d0586be0500       | cmp                 eax, -1
            //   eb2c                 | jne                 0x451

        $sequence_1 = { 0fb71482 e8???????? 488d054617feff 448b8498301b0500 4585c0 7411 2bb49f741e0000 }
            // n = 7, score = 100
            //   0fb71482             | dec                 eax
            //   e8????????           |                     
            //   488d054617feff       | mov                 dword ptr [esp + 0x670], eax
            //   448b8498301b0500     | dec                 eax
            //   4585c0               | mov                 ebx, ecx
            //   7411                 | dec                 eax
            //   2bb49f741e0000       | mov                 esi, edx

        $sequence_2 = { 4881ec500d0000 48c78550010000feffffff 48899c24a00d0000 488b05???????? 4833c4 488985400c0000 488bf2 }
            // n = 7, score = 100
            //   4881ec500d0000       | dec                 eax
            //   48c78550010000feffffff     | lea    ecx, [0x3f648]
            //   48899c24a00d0000     | call                eax
            //   488b05????????       |                     
            //   4833c4               | mov                 dl, 0xf
            //   488985400c0000       | mov                 ecx, eax
            //   488bf2               | dec                 eax

        $sequence_3 = { 488b01 488d5590 ff5048 85c0 7957 448bc0 488d15c4f20400 }
            // n = 7, score = 100
            //   488b01               | dec                 eax
            //   488d5590             | mov                 ecx, ebx
            //   ff5048               | dec                 eax
            //   85c0                 | lea                 ecx, [esp + 0x4c]
            //   7957                 | inc                 ebp
            //   448bc0               | xor                 ecx, ecx
            //   488d15c4f20400       | inc                 ebp

        $sequence_4 = { 448bc0 488d1516e60400 488d4d50 e8???????? 33c0 4883c9ff 488d7d50 }
            // n = 7, score = 100
            //   448bc0               | dec                 eax
            //   488d1516e60400       | mov                 ecx, eax
            //   488d4d50             | dec                 eax
            //   e8????????           |                     
            //   33c0                 | mov                 edx, ebx
            //   4883c9ff             | mov                 ecx, 0x40
            //   488d7d50             | call                eax

        $sequence_5 = { 48899c24e0040000 488b5c2448 4c89bc2490040000 4883c308 4c8d3d63780500 8b03 83f8ff }
            // n = 7, score = 100
            //   48899c24e0040000     | dec                 eax
            //   488b5c2448           | mov                 ecx, dword ptr [esp + 0x30]
            //   4c89bc2490040000     | dec                 eax
            //   4883c308             | lea                 ecx, [esp + 0x40]
            //   4c8d3d63780500       | inc                 ecx
            //   8b03                 | mov                 ecx, 1
            //   83f8ff               | dec                 eax

        $sequence_6 = { 488b01 ff5010 e9???????? 488b4c2460 488b01 4533c0 488d9520080000 }
            // n = 7, score = 100
            //   488b01               | dec                 eax
            //   ff5010               | lea                 ecx, [ebp - 0x20]
            //   e9????????           |                     
            //   488b4c2460           | dec                 eax
            //   488b01               | lea                 ecx, [esp + 0x68]
            //   4533c0               | dec                 esp
            //   488d9520080000       | lea                 eax, [ebp - 0x10]

        $sequence_7 = { 33c0 4883c440 415d 5e 5b c3 48896c2460 }
            // n = 7, score = 100
            //   33c0                 | mov                 dword ptr [esp + 0xd10], ebx
            //   4883c440             | dec                 eax
            //   415d                 | xor                 eax, esp
            //   5e                   | dec                 eax
            //   5b                   | mov                 dword ptr [ebp + 0xbc0], eax
            //   c3                   | dec                 eax
            //   48896c2460           | mov                 ebx, edx

        $sequence_8 = { 741b 488d0d4e4d0300 e8???????? 488b0d???????? ffd0 8b05???????? 4c8925???????? }
            // n = 7, score = 100
            //   741b                 | dec                 eax
            //   488d0d4e4d0300       | mov                 dword ptr [esp + 0x50], esi
            //   e8????????           |                     
            //   488b0d????????       |                     
            //   ffd0                 | dec                 eax
            //   8b05????????         |                     
            //   4c8925????????       |                     

        $sequence_9 = { 488bce e8???????? 85c0 7505 8d5804 eb4d 488d152d3c0500 }
            // n = 7, score = 100
            //   488bce               | mov                 ebx, esi
            //   e8????????           |                     
            //   85c0                 | dec                 eax
            //   7505                 | lea                 eax, [0x47a2b]
            //   8d5804               | dec                 eax
            //   eb4d                 | not                 ecx
            //   488d152d3c0500       | dec                 esp

    condition:
        7 of them and filesize < 1399808
}
Download all Yara Rules