SYMBOLCOMMON_NAMEaka. SYNONYMS
win.miniblindingcan (Back to overview)

miniBlindingCan

aka: AIRDRY.V2, EventHorizon

Actor(s): Lazarus Group

VTCollection    

miniBlindingCan is an HTTP(S) orchestrator.

It is a variant of the BlindingCan RAT, having the same command parsing logic, but supporting only a small subset of commands available previously. The main operations are the update of the malware configuration, and the download and execution of additional payloads from the attackers' C&C.

The miniBlindingCan malware was used in Operation DreamJob attacks against aerospace and media companies in Q2-Q3 2022.

References
2023-10-04 ⋅ Virus Bulletin ⋅ Peter Kálnai
Lazarus Campaigns and Backdoors in 2022-23
SimpleTea POOLRAT 3CX Backdoor BLINDINGCAN CLOUDBURST DRATzarus ForestTiger ImprudentCook LambLoad LightlessCan miniBlindingCan PostNapTea SecondHandTea SnatchCrypto wAgentTea WebbyTea WinInetLoader
2023-09-29 ⋅ ESET Research ⋅ Peter Kálnai
Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
CLOUDBURST LightlessCan miniBlindingCan sRDI
2022-09-29 ⋅ Microsoft ⋅ LinkedIn Threat Prevention and Defense, Microsoft Security Threat Intelligence
ZINC weaponizing open-source software
BLINDINGCAN CLOUDBURST miniBlindingCan
2022-09-14 ⋅ Mandiant ⋅ James Maclachlan, Mathew Potaczek, Matt Williams, Nino Isakovic, Yash Gupta
It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp
BLINDINGCAN miniBlindingCan sRDI
Yara Rules
[TLP:WHITE] win_miniblindingcan_auto (20260917 | Detects win.miniblindingcan.)
rule win_miniblindingcan_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.miniblindingcan."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.miniblindingcan"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b5db3 448d241f b940000000 488945b7 418bd4 ff15???????? 448bc3 }
            // n = 7, score = 100
            //   8b5db3               | je                  0xd0a
            //   448d241f             | mov                 edx, ebp
            //   b940000000           | cmp                 dword ptr [esi + 0x18], eax
            //   488945b7             | jbe                 0xd55
            //   418bd4               | dec                 esp
            //   ff15????????         |                     
            //   448bc3               | mov                 esp, dword ptr [esp + 0x68]

        $sequence_1 = { 7513 488d053b320000 488905???????? e9???????? 81fbf0550000 7513 488d0515320000 }
            // n = 7, score = 100
            //   7513                 | mov                 ecx, dword ptr [esp + 0x58]
            //   488d053b320000       | mov                 dword ptr [esp + 0x48], 2
            //   488905????????       |                     
            //   e9????????           |                     
            //   81fbf0550000         | dec                 eax
            //   7513                 | lea                 eax, [esp + 0x54]
            //   488d0515320000       | test                eax, eax

        $sequence_2 = { 89742450 89742460 ba04010000 4c2bc0 488d8d90030000 488d82fafeff7f 4885c0 }
            // n = 7, score = 100
            //   89742450             | xor                 edx, edx
            //   89742460             | xor                 edx, edx
            //   ba04010000           | mov                 word ptr [ebp + 0x5f0], si
            //   4c2bc0               | dec                 eax
            //   488d8d90030000       | mov                 ecx, edi
            //   488d82fafeff7f       | mov                 dword ptr [esp + 0x48], esi
            //   4885c0               | mov                 dword ptr [esp + 0x40], esi

        $sequence_3 = { e8???????? cc b201 488bcf e8???????? 4c8d1d2b880000 488d5547 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   cc                   | mov                 dword ptr [ebp + 0x40], 0x74006e
            //   b201                 | inc                 ecx
            //   488bcf               | mov                 eax, 0x20
            //   e8????????           |                     
            //   4c8d1d2b880000       | dec                 eax
            //   488d5547             | lea                 edx, [0x26135]

        $sequence_4 = { 488d0576be0000 488bd9 488901 c6411000 e8???????? }
            // n = 5, score = 100
            //   488d0576be0000       | push                esp
            //   488bd9               | inc                 ecx
            //   488901               | push                ebp
            //   c6411000             | dec                 eax
            //   e8????????           |                     

        $sequence_5 = { c3 4c8bd1 b83f000000 0f05 }
            // n = 4, score = 100
            //   c3                   | dec                 ebp
            //   4c8bd1               | mov                 esp, eax
            //   b83f000000           | dec                 eax
            //   0f05                 | lea                 ecx, [esp + 0x30]

        $sequence_6 = { e9???????? 8a03 488d15410b0200 ffc7 4a8b0ce2 4188440f4c 4a8b04e2 }
            // n = 7, score = 100
            //   e9????????           |                     
            //   8a03                 | xor                 eax, dword ptr [esp + eax*4 + 0x20a60]
            //   488d15410b0200       | inc                 ebp
            //   ffc7                 | xor                 ecx, dword ptr [ebp + 0x68]
            //   4a8b0ce2             | movzx               eax, bl
            //   4188440f4c           | inc                 ebp
            //   4a8b04e2             | xor                 eax, dword ptr [esp + eax*4 + 0x20e60]

        $sequence_7 = { 4833c4 48898570040000 488bf9 488d4c2471 33d2 }
            // n = 5, score = 100
            //   4833c4               | lea                 eax, [0x42e6]
            //   48898570040000       | cmp                 ebx, 0x4a61
            //   488bf9               | jne                 0x145e
            //   488d4c2471           | dec                 eax
            //   33d2                 | lea                 eax, [0x40e9]

        $sequence_8 = { 55 488da8f8f1ffff 4881ec000f0000 488b05???????? 4833c4 488985f00d0000 33f6 }
            // n = 7, score = 100
            //   55                   | mov                 ebx, eax
            //   488da8f8f1ffff       | mov                 eax, 0x7482296b
            //   4881ec000f0000       | imul                ebx
            //   488b05????????       |                     
            //   4833c4               | sar                 edx, 0xc
            //   488985f00d0000       | jmp                 0x13ea
            //   33f6                 | mov                 edx, 0x24b0

        $sequence_9 = { 8bc2 4803f0 448806 48ffc6 eb1d 480fbcc0 89bc24b0000000 }
            // n = 7, score = 100
            //   8bc2                 | mov                 eax, dword ptr [edi]
            //   4803f0               | inc                 ecx
            //   448806               | cmp                 eax, dword ptr [esp]
            //   48ffc6               | jne                 0xf3b
            //   eb1d                 | cmp                 eax, ebx
            //   480fbcc0             | je                  0xf38
            //   89bc24b0000000       | xor                 eax, eax

    condition:
        7 of them and filesize < 453632
}
Download all Yara Rules