SYMBOLCOMMON_NAMEaka. SYNONYMS
win.scoring_math_tea (Back to overview)

ScoringMathTea

Actor(s): Lazarus Group

VTCollection    

According to ESET Research, ScoringMathTea is a RAT that offers the attackers full control over the compromised machine. Its first appearance dates to late 2022, when its dropper was uploaded to VirusTotal. Soon after, it was seen in the wild, and since then in multiple attacks attributed to Lazarus’ Operation DreamJob campaigns, which makes it the attacker’s payload of choice for already three years. It uses compromised servers for C&C communication, with the server part usually stored under the WordPress folder containing design templates or plugins.

References
2025-11-17 ⋅ 0x0d4y ⋅ 0x0d4y
Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea
ScoringMathTea
2025-11-05 ⋅ ESET Research ⋅ ESET Research
ESET APT Activity Report (April 2025 – September 2025): Russia-Aligned APTs Ramp Up Attacks Against Ukraine and Its Strategic Partners
BACKORDER BloodAlchemy ImprudentCook RokRAT ScoringMathTea
2025-10-23 ⋅ ESET Research ⋅ Alexis Rapin, Peter Kálnai
Gotta fly: Lazarus targets the UAV sector
BURNBOOK QuanPinLoader ScoringMathTea
Yara Rules
[TLP:WHITE] win_scoring_math_tea_auto (20260917 | Detects win.scoring_math_tea.)
rule win_scoring_math_tea_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.scoring_math_tea."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.scoring_math_tea"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 448bc3 33d2 488d8da0030000 e8???????? 448bc3 33d2 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   448bc3               | sub                 eax, eax
            //   33d2                 | dec                 esp
            //   488d8da0030000       | mov                 edx, ecx
            //   e8????????           |                     
            //   448bc3               | je                  0x1cf
            //   33d2                 | dec                 eax

        $sequence_1 = { 4883f801 410f45fd 85ff 753d 4d85f6 742c 0f2845b0 }
            // n = 7, score = 100
            //   4883f801             | mov                 eax, dword ptr [esp + 0x48]
            //   410f45fd             | dec                 eax
            //   85ff                 | cmp                 eax, -1
            //   753d                 | je                  0x25b
            //   4d85f6               | dec                 eax
            //   742c                 | mov                 edx, ebx
            //   0f2845b0             | dec                 esp

        $sequence_2 = { 72bf b9f5728387 e8???????? 498bcf ffd0 4533ff 4885f6 }
            // n = 7, score = 100
            //   72bf                 | dec                 eax
            //   b9f5728387           | lea                 eax, [esi + 0x18]
            //   e8????????           |                     
            //   498bcf               | dec                 eax
            //   ffd0                 | mov                 dword ptr [esp + 0x30], eax
            //   4533ff               | dec                 eax
            //   4885f6               | mov                 dword ptr [esp + 0x28], edx

        $sequence_3 = { 33f6 eb38 833b02 7407 b800000800 eb2c }
            // n = 6, score = 100
            //   33f6                 | mov                 ebx, dword ptr [esi + ecx*4]
            //   eb38                 | dec                 eax
            //   833b02               | add                 ebx, edx
            //   7407                 | dec                 esp
            //   b800000800           | lea                 ecx, [0x102]
            //   eb2c                 | mov                 edx, 0x108

        $sequence_4 = { ffd0 3d02010000 74cc b9380f2fc0 e8???????? 488d542430 498bce }
            // n = 7, score = 100
            //   ffd0                 | je                  0x54b
            //   3d02010000           | mov                 ecx, 0x1b4c7527
            //   74cc                 | xor                 edx, edx
            //   b9380f2fc0           | dec                 eax
            //   e8????????           |                     
            //   488d542430           | mov                 ecx, esi
            //   498bce               | call                eax

        $sequence_5 = { 4883f9fd 7706 ff15???????? 488364243000 488d0d4cfc0000 8364242800 }
            // n = 6, score = 100
            //   4883f9fd             | mov                 eax, ebx
            //   7706                 | dec                 eax
            //   ff15????????         |                     
            //   488364243000         | mov                 ebx, dword ptr [esp + 0x40]
            //   488d0d4cfc0000       | xor                 edx, edx
            //   8364242800           | dec                 eax

        $sequence_6 = { 4c8d0523490100 e8???????? 488bcb 4885c0 740a 8bd7 ff15???????? }
            // n = 7, score = 100
            //   4c8d0523490100       | inc                 esp
            //   e8????????           |                     
            //   488bcb               | cmp                 esi, eax
            //   4885c0               | inc                 ecx
            //   740a                 | mov                 edx, esp
            //   8bd7                 | inc                 esp
            //   ff15????????         |                     

        $sequence_7 = { 7873 3b1d???????? 736b 488bc3 488bf3 48c1fe06 4c8d2d1ec90200 }
            // n = 7, score = 100
            //   7873                 | mov                 ecx, dword ptr [edi + 0x2563]
            //   3b1d????????         |                     
            //   736b                 | dec                 eax
            //   488bc3               | mov                 ecx, ebx
            //   488bf3               | dec                 eax
            //   48c1fe06             | test                ebx, ebx
            //   4c8d2d1ec90200       | jne                 0x35c

        $sequence_8 = { 488d7b7d 4c8dbd20010000 498b5d00 e8???????? 33d2 4898 48f7f3 }
            // n = 7, score = 100
            //   488d7b7d             | inc                 ecx
            //   4c8dbd20010000       | lea                 eax, [ebx + edx]
            //   498b5d00             | cmp                 eax, ecx
            //   e8????????           |                     
            //   33d2                 | ja                  0x364
            //   4898                 | inc                 ecx
            //   48f7f3               | cmp                 eax, 0x10

        $sequence_9 = { 488d056eb80400 488983f0af0600 488bcb e8???????? 4585f6 7408 e8???????? }
            // n = 7, score = 100
            //   488d056eb80400       | mov                 dword ptr [ebp - 0x2c], ecx
            //   488983f0af0600       | dec                 eax
            //   488bcb               | lea                 ecx, [ebp - 0x30]
            //   e8????????           |                     
            //   4585f6               | inc                 esp
            //   7408                 | mov                 ebp, dword ptr [ebp - 0x30]
            //   e8????????           |                     

    condition:
        7 of them and filesize < 881664
}
Download all Yara Rules