SYMBOLCOMMON_NAMEaka. SYNONYMS
win.postnaptea (Back to overview)

PostNapTea

aka: SIGNBT

Actor(s): Lazarus Group

VTCollection    

PostNapTea aka SIGNBT is an HTTP(S) RAT that is written as a complex object-oriented project.

In 2022-2023, it was deployed against targets like a newspaper organization, agriculture-related entity or a software vendor. The initial access was usually achieved by exploiting vulnerabilities in widely-used software in South Korea.

It collects various information about the victim’s computer, such as computer name, product name, OS details, system uptime, CPU information, system locale, time zone, network status, and malware configuration.

PostNapTea uses AES for encryption and decryption ot network traffic. There is a constant prefix SIGNBT occuring in its HTTP POST requests. The prefix is concatenated with 2 characters that identify the communication stage:
• LG: logging into the C&C server
• KE: acknowledging the succesful login to the C&C
• FI: sending the status of a failed operation
• SR: sending the status of a successful operation
• GC: getting the next command

There are five classes that represent command groups:
• CCButton: for file manipulation and screen capturing
• CCBitmap: for network commands, implementing functionality of Windows commands often abused by attackers, like sc, reg, arp, net, ver, wmic, ping, whoami, netstat, tracert, lookup, ipconfig,
systeminfo, and netsh advfirewall.
• CCComboBox: for file system management
• CCList: for process management
• CCBrush: for control of the malware itself

It stores its configuration in JSON format. It resolves the Windows APIs it requires during runtime, via the Fowler–Noll–Vo (FNV) hash function.

Its internal name in the version-information resource is usually ppcsnap.dll or pconsnap.dll, which loosely inspired its code name.

References
2026-07-30 ⋅ AhnLab ⋅ ASEC
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
Bankshot Gunra PostNapTea
2025-07-28 ⋅ Wiz.io ⋅ Merav Bar
TraderTraitor: Deep Dive
GolangGhost Manuscrypt RN Stealer DRATzarus GolangGhost PostNapTea Volgmer wAgentTea
2025-04-24 ⋅ Kaspersky ⋅ Sojun Ryu, Vasily Berdnikov
Operation SyncHole: Lazarus APT goes back to the well
Bankshot DRATzarus PostNapTea wAgentTea
2023-10-27 ⋅ Kaspersky ⋅ Seongsu Park
A cascade of compromise: unveiling Lazarus’ new campaign
LPEClient PostNapTea
2023-10-04 ⋅ Virus Bulletin ⋅ Peter Kálnai
Lazarus Campaigns and Backdoors in 2022-23
SimpleTea POOLRAT 3CX Backdoor BLINDINGCAN CLOUDBURST DRATzarus ForestTiger ImprudentCook LambLoad LightlessCan miniBlindingCan PostNapTea SecondHandTea SnatchCrypto wAgentTea WebbyTea WinInetLoader
Yara Rules
[TLP:WHITE] win_postnaptea_auto (20260917 | Detects win.postnaptea.)
rule win_postnaptea_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.postnaptea."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.postnaptea"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4c8930 488b4638 4c8930 488b4650 448930 488d053ebf0600 488906 }
            // n = 7, score = 100
            //   4c8930               | add                 ecx, edx
            //   488b4638             | inc                 ecx
            //   4c8930               | add                 dword ptr [edx + 4], ecx
            //   488b4650             | inc                 ecx
            //   448930               | add                 dword ptr [edx + 8], edx
            //   488d053ebf0600       | inc                 ecx
            //   488906               | mov                 dword ptr [eax + edx*4], eax

        $sequence_1 = { f30f1084059c060000 f30f58840598060000 f30f118c8d900a0000 f30f104c058c f30f584c0588 f30f588405d8060000 f30f584c05c8 }
            // n = 7, score = 100
            //   f30f1084059c060000     | dec    eax
            //   f30f58840598060000     | test    eax, eax
            //   f30f118c8d900a0000     | je    0x3ed
            //   f30f104c058c         | mov                 dword ptr [esp + 0x78], 0x18
            //   f30f584c0588         | dec                 eax
            //   f30f588405d8060000     | lea    ecx, [ebp - 0x60]
            //   f30f584c05c8         | dec                 eax

        $sequence_2 = { c745a4a00f0000 48895de8 33d2 41b880000000 488d8d40130000 e8???????? 33d2 }
            // n = 7, score = 100
            //   c745a4a00f0000       | mov                 dword ptr [ebp - 0x31], edi
            //   48895de8             | dec                 eax
            //   33d2                 | test                edi, edi
            //   41b880000000         | jne                 0xa1d
            //   488d8d40130000       | inc                 ebp
            //   e8????????           |                     
            //   33d2                 | xor                 eax, eax

        $sequence_3 = { e8???????? 4c8b05???????? 488905???????? 498bc8 ffd0 4c8b05???????? 4d85c0 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   4c8b05????????       |                     
            //   488905????????       |                     
            //   498bc8               | dec                 eax
            //   ffd0                 | add                 ebx, 6
            //   4c8b05????????       |                     
            //   4d85c0               | jmp                 0xd21

        $sequence_4 = { c7456cd4f588f5 c7457093f5a0f5 c74574c2f5c2f5 c74578def5daf5 c7457ccef5def5 c78580000000d2f5d7f5 c7858400000093f5dbf5 }
            // n = 7, score = 100
            //   c7456cd4f588f5       | mov                 eax, dword ptr [ecx]
            //   c7457093f5a0f5       | call                dword ptr [eax + 0x10]
            //   c74574c2f5c2f5       | dec                 eax
            //   c74578def5daf5       | mov                 eax, dword ptr [ecx]
            //   c7457ccef5def5       | call                dword ptr [eax + 0x10]
            //   c78580000000d2f5d7f5     | dec    eax
            //   c7858400000093f5dbf5     | mov    ecx, dword ptr [ebp + 0x18]

        $sequence_5 = { c7858c000000eaf5b0f5 c78590000000abf5b2f5 c78594000000b6f5f0f5 33c0 66898598000000 418bd6 0f1f840000000000 }
            // n = 7, score = 100
            //   c7858c000000eaf5b0f5     | mov    edx, dword ptr [ebp - 0x78]
            //   c78590000000abf5b2f5     | dec    eax
            //   c78594000000b6f5f0f5     | cmp    edx, 0x10
            //   33c0                 | jb                  0x18a0
            //   66898598000000       | dec                 eax
            //   418bd6               | inc                 edx
            //   0f1f840000000000     | dec                 eax

        $sequence_6 = { e8???????? 488905???????? 498bcd ffd0 488b4de8 ff15???????? 488b4df0 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   488905????????       |                     
            //   498bcd               | inc                 ecx
            //   ffd0                 | inc                 eax
            //   488b4de8             | inc                 ecx
            //   ff15????????         |                     
            //   488b4df0             | cmp                 eax, 3

        $sequence_7 = { ffd0 448be8 85c0 740b 3d03010000 0f85b7010000 8b4d03 }
            // n = 7, score = 100
            //   ffd0                 | mov                 dword ptr [ebp + 0x66c], 0xf51ef57b
            //   448be8               | mov                 dword ptr [ebp + 0x670], 0xf537f528
            //   85c0                 | mov                 dword ptr [ebp + 0x674], 0xf504f533
            //   740b                 | mov                 dword ptr [ebp + 0x678], 0xf536f541
            //   3d03010000           | dec                 eax
            //   0f85b7010000         | lea                 ecx, [ebp + 0xf10]
            //   8b4d03               | mov                 dword ptr [ebp + 0xb70], 0xf533f50f

        $sequence_8 = { c785f80000007cf577f5 c785fc00000069f56bf5 c785000100002ef50000 418bd0 660f1f840000000000 4863c2 488d8df8000000 }
            // n = 7, score = 100
            //   c785f80000007cf577f5     | je    0x1873
            //   c785fc00000069f56bf5     | dec    eax
            //   c785000100002ef50000     | mov    eax, dword ptr [ecx]
            //   418bd0               | call                dword ptr [eax + 0x20]
            //   660f1f840000000000     | dec    eax
            //   4863c2               | lea                 eax, [0x4d853]
            //   488d8df8000000       | dec                 eax

        $sequence_9 = { c785c0040000eaf5e5f5 c785c4040000eff5e9f5 c785c8040000adf5b4f5 c785cc040000aff50000 33ff 8bd7 0f1f840000000000 }
            // n = 7, score = 100
            //   c785c0040000eaf5e5f5     | dec    eax
            //   c785c4040000eff5e9f5     | cmove    ebx, eax
            //   c785c8040000adf5b4f5     | dec    eax
            //   c785cc040000aff50000     | mov    edx, ebx
            //   33ff                 | dec                 eax
            //   8bd7                 | mov                 ebx, dword ptr [esp + 0x30]
            //   0f1f840000000000     | dec                 eax

    condition:
        7 of them and filesize < 2457600
}
Download all Yara Rules