SYMBOLCOMMON_NAMEaka. SYNONYMS
win.mltbackdoor (Back to overview)

MLTBackdoor

VTCollection    

According to Zscaler, MLTBackdoor is a Windows post-exploitation backdoor likely written in C/C++ and compiled with an LLVM-based obfuscator that applies heavy mixed boolean-arithmetic and control-flow flattening, plus DJB2-based API hashing and indirect system calls to hinder analysis and evade hooks. It uses a custom binary protocol over TLS with elliptic-curve Diffie-Hellman key exchange and AES-GCM for encrypted C2 traffic, and includes a date-based domain generation algorithm (DGA) to maintain contact if primary C2 domains are unavailable. Natively, it provides a focused set of filesystem commands for uploading, downloading, listing, deleting, renaming, and creating files and folders. Its key feature is a built-in Beacon Object File loader compatible with a subset of Cobalt Strike-style BOF imports and its own syscall wrappers, allowing operators to dynamically extend capabilities for activities such as discovery, credential access, and lateral movement, which Zscaler links to ransomware-oriented operations.

References
2026-06-09 ⋅ Zscaler ⋅ ThreatLabZ research team
Technical Analysis of MLTBackdoor
MLTBackdoor
Yara Rules
[TLP:WHITE] win_mltbackdoor_auto (20260917 | Detects win.mltbackdoor.)
rule win_mltbackdoor_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.mltbackdoor."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mltbackdoor"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c1e104 8d0489 29c2 416bc0af 8d0c02 83c1af 01c2 }
            // n = 7, score = 100
            //   c1e104               | not                 ecx
            //   8d0489               | inc                 esp
            //   29c2                 | mov                 edx, ecx
            //   416bc0af             | or                  edx, 1
            //   8d0c02               | inc                 esp
            //   83c1af               | xor                 edx, ecx
            //   01c2                 | inc                 ecx

        $sequence_1 = { e9???????? 488b4c2458 4889f2 e8???????? c744243400000000 8b0d???????? 89ca }
            // n = 7, score = 100
            //   e9????????           |                     
            //   488b4c2458           | add                 ecx, edx
            //   4889f2               | add                 ecx, eax
            //   e8????????           |                     
            //   c744243400000000     | inc                 ecx
            //   8b0d????????         |                     
            //   89ca                 | shl                 eax, 2

        $sequence_2 = { ffc8 446bd047 f7d0 6bc046 4401d0 4101c0 4181c0ab000000 }
            // n = 7, score = 100
            //   ffc8                 | inc                 ecx
            //   446bd047             | sub                 edx, esi
            //   f7d0                 | inc                 edi
            //   6bc046               | lea                 ebx, [ebx + ebx*8]
            //   4401d0               | inc                 edi
            //   4101c0               | lea                 ebx, [ebx + ebx*2]
            //   4181c0ab000000       | not                 esi

        $sequence_3 = { c1e607 8d34be 89d7 21cf 41f7d3 4569db83000000 4101f3 }
            // n = 7, score = 100
            //   c1e607               | inc                 ecx
            //   8d34be               | add                 eax, -0x38
            //   89d7                 | add                 edx, ecx
            //   21cf                 | inc                 ecx
            //   41f7d3               | not                 eax
            //   4569db83000000       | inc                 ecx
            //   4101f3               | imul                ecx, eax, 0x4b

        $sequence_4 = { bad50c2236 e8???????? 4c8b542468 4c89a42418010000 66490f6ec4 4c89ac2468010000 66490f6ecd }
            // n = 7, score = 100
            //   bad50c2236           | add                 ecx, ecx
            //   e8????????           |                     
            //   4c8b542468           | inc                 ecx
            //   4c89a42418010000     | sub                 ecx, esi
            //   66490f6ec4           | inc                 ecx
            //   4c89ac2468010000     | add                 ecx, ebp
            //   66490f6ecd           | lea                 esi, [edx*8]

        $sequence_5 = { f7d2 6bca38 6bc039 01c8 0527deffff f7d0 05c6921e9f }
            // n = 7, score = 100
            //   f7d2                 | add                 edx, eax
            //   6bca38               | add                 edx, 0x9b2
            //   6bc039               | not                 edx
            //   01c8                 | inc                 esp
            //   0527deffff           | lea                 eax, [edx + edx*8]
            //   f7d0                 | inc                 edx
            //   05c6921e9f           | lea                 edx, [edx + eax*8]

        $sequence_6 = { f7d0 6bc088 456bc189 4401c0 0522ddffff 6bc9e2 4189d0 }
            // n = 7, score = 100
            //   f7d0                 | not                 edx
            //   6bc088               | inc                 ecx
            //   456bc189             | lea                 ecx, [eax - 1]
            //   4401c0               | inc                 ecx
            //   0522ddffff           | add                 eax, 0xa2
            //   6bc9e2               | add                 ecx, eax
            //   4189d0               | inc                 ecx

        $sequence_7 = { f7d0 6bc07c 01c8 83c07b 6bc863 f7d0 6bc062 }
            // n = 7, score = 100
            //   f7d0                 | imul                ecx, edx, 0xffffff74
            //   6bc07c               | inc                 ebp
            //   01c8                 | add                 eax, ecx
            //   83c07b               | inc                 ecx
            //   6bc863               | add                 eax, 0xffffaab0
            //   f7d0                 | inc                 ebp
            //   6bc062               | imul                ecx, eax, -0x2e

        $sequence_8 = { f7d1 89ca 81e2f97eaf02 81e10681507d 4189c0 4181e0f97eaf82 8d14d2 }
            // n = 7, score = 100
            //   f7d1                 | inc                 ecx
            //   89ca                 | add                 ecx, ebx
            //   81e2f97eaf02         | inc                 ebp
            //   81e10681507d         | add                 eax, ecx
            //   4189c0               | inc                 ecx
            //   4181e0f97eaf82       | add                 eax, 0x46
            //   8d14d2               | inc                 ecx

        $sequence_9 = { f7d1 89c7 09cf 4589d9 4121d1 4589d8 4121c8 }
            // n = 7, score = 100
            //   f7d1                 | add                 eax, 0xfffffde7
            //   89c7                 | inc                 ebp
            //   09cf                 | mov                 ecx, eax
            //   4589d9               | inc                 ecx
            //   4121d1               | add                 eax, 7
            //   4589d8               | inc                 ecx
            //   4121c8               | not                 eax

    condition:
        7 of them and filesize < 3367936
}
Download all Yara Rules