SYMBOLCOMMON_NAMEaka. SYNONYMS
win.nachocheese (Back to overview)

NACHOCHEESE

aka: Cyruslish, TWOPENCE, VIVACIOUSGIFT

Actor(s): Lazarus Group

VTCollection    

According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors shell access to a victim's system.

References
2020-08-26 ⋅ CISA ⋅ CISA
MAR-10301706-2.v1 - North Korean Remote Access Tool: VIVACIOUSGIFT
NACHOCHEESE
2020-02-19 ⋅ Lexfo ⋅ Lexfo
The Lazarus Constellation A study on North Korean malware
FastCash AppleJeus BADCALL Bankshot Brambul Dtrack Duuzer DYEPACK ELECTRICFISH HARDRAIN Hermes HOPLIGHT Joanap KEYMARBLE Kimsuky MimiKatz MyDoom NACHOCHEESE NavRAT PowerRatankba RokRAT Sierra(Alfa,Bravo, ...) Volgmer WannaCryptor
2018-10-03 ⋅ Virus Bulletin ⋅ Michal Poslušný, Peter Kálnai
Lazarus Group A Mahjong Game Played with Different Sets of Tiles
Bankshot BanPolMex RAT FuwuqiDrama HOTWAX KillDisk (Lazarus) NACHOCHEESE REDSHAWL WannaCryptor
2018-01-01 ⋅ FireEye ⋅ FireEye
APT38
CHEESETRAY CLEANTOAD NACHOCHEESE
2017-05-30 ⋅ Group-IB ⋅ Group-IB
Lazarus Arisen: Architecture, Techniques and Attribution
HOTWAX NACHOCHEESE Ratankba
2017-02-20 ⋅ BAE Systems ⋅ Sergei Shevchenko
Lazarus’ False Flag Malware
HOTWAX NACHOCHEESE
2017-02-16 ⋅ ESET Research ⋅ Peter Kálnai
Demystifying targeted malware used against Polish banks
BanPolMex RAT HOTWAX NACHOCHEESE
Yara Rules
[TLP:WHITE] win_nachocheese_auto (20260917 | Detects win.nachocheese.)
rule win_nachocheese_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.nachocheese."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nachocheese"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 6a01 688d000000 56 e8???????? 50 }
            // n = 6, score = 300
            //   e8????????           |                     
            //   6a01                 | push                1
            //   688d000000           | push                0x8d
            //   56                   | push                esi
            //   e8????????           |                     
            //   50                   | push                eax

        $sequence_1 = { 3d2bc00000 7d1b 3d9c000000 7c07 }
            // n = 4, score = 300
            //   3d2bc00000           | cmp                 eax, 0xc02b
            //   7d1b                 | jge                 0x1d
            //   3d9c000000           | cmp                 eax, 0x9c
            //   7c07                 | jl                  9

        $sequence_2 = { c3 8d85ecfaffff 68???????? 50 e8???????? 83c408 85c0 }
            // n = 7, score = 300
            //   c3                   | ret                 
            //   8d85ecfaffff         | lea                 eax, [ebp - 0x514]
            //   68????????           |                     
            //   50                   | push                eax
            //   e8????????           |                     
            //   83c408               | add                 esp, 8
            //   85c0                 | test                eax, eax

        $sequence_3 = { 81fb00000100 7305 83c304 eb0f }
            // n = 4, score = 300
            //   81fb00000100         | cmp                 ebx, 0x10000
            //   7305                 | jae                 7
            //   83c304               | add                 ebx, 4
            //   eb0f                 | jmp                 0x11

        $sequence_4 = { 85c0 741c 8b8de8faffff 68???????? }
            // n = 4, score = 300
            //   85c0                 | test                eax, eax
            //   741c                 | je                  0x1e
            //   8b8de8faffff         | mov                 ecx, dword ptr [ebp - 0x518]
            //   68????????           |                     

        $sequence_5 = { 33c8 894710 8b4708 33c1 }
            // n = 4, score = 300
            //   33c8                 | xor                 ecx, eax
            //   894710               | mov                 dword ptr [edi + 0x10], eax
            //   8b4708               | mov                 eax, dword ptr [edi + 8]
            //   33c1                 | xor                 eax, ecx

        $sequence_6 = { 7f05 83e830 eb03 83e837 }
            // n = 4, score = 300
            //   7f05                 | jg                  7
            //   83e830               | sub                 eax, 0x30
            //   eb03                 | jmp                 5
            //   83e837               | sub                 eax, 0x37

        $sequence_7 = { 3d9f000000 7e0d 33c0 c3 }
            // n = 4, score = 300
            //   3d9f000000           | cmp                 eax, 0x9f
            //   7e0d                 | jle                 0xf
            //   33c0                 | xor                 eax, eax
            //   c3                   | ret                 

        $sequence_8 = { 33c0 c3 05d13fffff 83f801 }
            // n = 4, score = 300
            //   33c0                 | xor                 eax, eax
            //   c3                   | ret                 
            //   05d13fffff           | add                 eax, 0xffff3fd1
            //   83f801               | cmp                 eax, 1

        $sequence_9 = { 3d2cc00000 7f18 3d2bc00000 7d1b }
            // n = 4, score = 300
            //   3d2cc00000           | cmp                 eax, 0xc02c
            //   7f18                 | jg                  0x1a
            //   3d2bc00000           | cmp                 eax, 0xc02b
            //   7d1b                 | jge                 0x1d

        $sequence_10 = { 52 66894b02 ff15???????? 8bf0 }
            // n = 4, score = 300
            //   52                   | push                edx
            //   66894b02             | mov                 word ptr [ebx + 2], cx
            //   ff15????????         |                     
            //   8bf0                 | mov                 esi, eax

        $sequence_11 = { 8895f0fcffff 8d95f1fcffff 6a00 52 e8???????? 6a3a 68???????? }
            // n = 7, score = 300
            //   8895f0fcffff         | mov                 byte ptr [ebp - 0x310], dl
            //   8d95f1fcffff         | lea                 edx, [ebp - 0x30f]
            //   6a00                 | push                0
            //   52                   | push                edx
            //   e8????????           |                     
            //   6a3a                 | push                0x3a
            //   68????????           |                     

        $sequence_12 = { 3d9c000000 7c07 3d9f000000 7e0d }
            // n = 4, score = 300
            //   3d9c000000           | cmp                 eax, 0x9c
            //   7c07                 | jl                  9
            //   3d9f000000           | cmp                 eax, 0x9f
            //   7e0d                 | jle                 0xf

        $sequence_13 = { 2bfa 8d47fd 3901 8901 }
            // n = 4, score = 300
            //   2bfa                 | sub                 edi, edx
            //   8d47fd               | lea                 eax, [edi - 3]
            //   3901                 | cmp                 dword ptr [ecx], eax
            //   8901                 | mov                 dword ptr [ecx], eax

        $sequence_14 = { 33f6 6a03 8bf9 8975f8 e8???????? 83c404 8975fc }
            // n = 7, score = 300
            //   33f6                 | xor                 esi, esi
            //   6a03                 | push                3
            //   8bf9                 | mov                 edi, ecx
            //   8975f8               | mov                 dword ptr [ebp - 8], esi
            //   e8????????           |                     
            //   83c404               | add                 esp, 4
            //   8975fc               | mov                 dword ptr [ebp - 4], esi

        $sequence_15 = { 8b55fc 880c3e 8a540205 32d1 8b4df8 88143e 8a4c0105 }
            // n = 7, score = 300
            //   8b55fc               | mov                 edx, dword ptr [ebp - 4]
            //   880c3e               | mov                 byte ptr [esi + edi], cl
            //   8a540205             | mov                 dl, byte ptr [edx + eax + 5]
            //   32d1                 | xor                 dl, cl
            //   8b4df8               | mov                 ecx, dword ptr [ebp - 8]
            //   88143e               | mov                 byte ptr [esi + edi], dl
            //   8a4c0105             | mov                 cl, byte ptr [ecx + eax + 5]

    condition:
        7 of them and filesize < 1064960
}
Download all Yara Rules