SYMBOLCOMMON_NAMEaka. SYNONYMS
win.spygrace (Back to overview)

SpyGrace

aka: SpyGlace

Actor(s): APT-C-60

VTCollection    

A backdoor, capable of providing shell access, loading additional payloads, interacting remotely with the file system and processes, and taking screenshots.

References
2024-12-11 ⋅ JPCERT/CC ⋅ Tomoya Kamei
Attack Exploiting Legitimate Service by APT-C-60
SpyGrace
2024-08-28 ⋅ ESET Research ⋅ ESET Research
ESET Research: Spy group exploits WPS Office zero day; analysis uncovers a second vulnerability
SpyGrace
2024-08-28 ⋅ ESET Research ⋅ Romain Dumont
Analysis of two arbitrary code execution vulnerabilities affecting WPS Office
SpyGrace
2022-12-20 ⋅ ThreatBook ⋅ ThreatBook
Analysis of APT-C-60 Attack on South Korea
SpyGrace
Yara Rules
[TLP:WHITE] win_spygrace_auto (20260917 | Detects win.spygrace.)
rule win_spygrace_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.spygrace."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.spygrace"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4c8d0db38f0300 448ac7 488bd1 488d4de7 }
            // n = 4, score = 100
            //   4c8d0db38f0300       | cmp                 edx, esi
            //   448ac7               | dec                 esp
            //   488bd1               | mov                 dword ptr [esi + 0x10], edi
            //   488d4de7             | dec                 eax

        $sequence_1 = { 33c0 e9???????? bdc8000000 488d5964 448bcd 4c8d0505ce0200 }
            // n = 6, score = 100
            //   33c0                 | mov                 ecx, 0x100
            //   e9????????           |                     
            //   bdc8000000           | rep stosd           dword ptr es:[edi], eax
            //   488d5964             | dec                 eax
            //   448bcd               | lea                 edi, [esi + 0x4e0]
            //   4c8d0505ce0200       | dec                 eax

        $sequence_2 = { e8???????? 48837df700 742f 41b804000000 488d1543e30200 488bcb e8???????? }
            // n = 7, score = 100
            //   e8????????           |                     
            //   48837df700           | mov                 byte ptr [ecx], al
            //   742f                 | inc                 ecx
            //   41b804000000         | lea                 edx, [eax + 0xf]
            //   488d1543e30200       | ret                 
            //   488bcb               | inc                 ebp
            //   e8????????           |                     

        $sequence_3 = { 4157 4883ec20 4c8b4110 488bf1 4d85c0 }
            // n = 5, score = 100
            //   4157                 | add                 ebx, ecx
            //   4883ec20             | inc                 ecx
            //   4c8b4110             | rol                 ebx, 7
            //   488bf1               | inc                 ebp
            //   4d85c0               | add                 ebx, ecx

        $sequence_4 = { e8???????? 488d4fff bafeffff7f 488bd8 483bca 7738 482bd7 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   488d4fff             | mov                 dword ptr [ebp - 0x75], 0xf
            //   bafeffff7f           | inc                 ecx
            //   488bd8               | mov                 eax, 1
            //   483bca               | dec                 eax
            //   7738                 | lea                 edx, [0x3799e]
            //   482bd7               | dec                 eax

        $sequence_5 = { eb12 4c8d0db1e20300 448ac3 498bd6 e8???????? 488d87c0020000 48396818 }
            // n = 7, score = 100
            //   eb12                 | dec                 eax
            //   4c8d0db1e20300       | lea                 edx, [ebp - 0x50]
            //   448ac3               | dec                 eax
            //   498bd6               | mov                 ecx, eax
            //   e8????????           |                     
            //   488d87c0020000       | dec                 esp
            //   48396818             | lea                 eax, [ebp - 0x30]

        $sequence_6 = { c645d800 488b5618 4883fa10 7228 48ffc2 488b0e }
            // n = 6, score = 100
            //   c645d800             | dec                 eax
            //   488b5618             | lea                 ecx, [ebp - 0x58]
            //   4883fa10             | mov                 eax, ebx
            //   7228                 | dec                 eax
            //   48ffc2               | mov                 ecx, dword ptr [ebp + 0x1d0]
            //   488b0e               | dec                 eax

        $sequence_7 = { 498bcd e8???????? 4889442448 4885c0 0f8419010000 448beb 488bce }
            // n = 7, score = 100
            //   498bcd               | lea                 ecx, [esp + 0x68]
            //   e8????????           |                     
            //   4889442448           | dec                 ecx
            //   4885c0               | or                  eax, 0xffffffff
            //   0f8419010000         | dec                 esp
            //   448beb               | mov                 esp, dword ptr [esp + 0x58]
            //   488bce               | dec                 ecx

        $sequence_8 = { 44897c2420 4c8d4da0 4c8d0537ab0300 ba00010000 488d4db0 e8???????? 41bf01000000 }
            // n = 7, score = 100
            //   44897c2420           | cmp                 dword ptr [ebp + 8], 8
            //   4c8d4da0             | inc                 ecx
            //   4c8d0537ab0300       | mov                 eax, 0x3f
            //   ba00010000           | dec                 ecx
            //   488d4db0             | lea                 edx, [edi + 0x288]
            //   e8????????           |                     
            //   41bf01000000         | dec                 eax

        $sequence_9 = { 4c8bf0 4885c0 0f8433030000 bb40000000 448bc3 33d2 488d4d10 }
            // n = 7, score = 100
            //   4c8bf0               | dec                 eax
            //   4885c0               | cmovb               eax, ecx
            //   0f8433030000         | dec                 esp
            //   bb40000000           | mov                 ecx, dword ptr [ebp - 0x20]
            //   448bc3               | dec                 esp
            //   33d2                 | mov                 eax, dword ptr [ebp - 0x28]
            //   488d4d10             | mov                 edx, 3

    condition:
        7 of them and filesize < 865280
}
Download all Yara Rules