SYMBOLCOMMON_NAMEaka. SYNONYMS
win.triback_loader (Back to overview)

TriBack Loader

VTCollection    

According to Group-IB, TriBack Loader is a custom shellcode loader used to deliver and execute secondary payloads in memory on targeted Windows systems. It operates through DLL sideloading, where a signed legitimate binary loads a malicious DLL that decrypts an encrypted companion file using a two-stage decryption routine consisting of byte reversal and rolling XOR with an offset. The decrypted shellcode is then executed via Win32 callback APIs such as InitOnceExecuteOnce, TimerQueue callbacks, or the undocumented EtwpCreateEtwThread, each chosen to evade detection by endpoint security products. Four observed variants indicate it is produced by a custom builder, with each variant rotating the callback API used for execution while maintaining the same decryption scheme and reflective loader mechanism for deploying final payloads.

References
2026-05-07 ⋅ Sophos ⋅ Chaitanya Ghorpade, Gabor Szappanos, Matt Wixey, Rahil Shah, Rahul Dugar
Donuts and Beagles: Fake Claude site spreads backdoor
TriBack Loader
Yara Rules
[TLP:WHITE] win_triback_loader_auto (20260917 | Detects win.triback_loader.)
rule win_triback_loader_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.triback_loader."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.triback_loader"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 7416 83f902 0f85c0010000 498bce e8???????? e9???????? 498bce }
            // n = 7, score = 100
            //   7416                 | dec                 eax
            //   83f902               | sub                 esp, 0x30
            //   0f85c0010000         | mov                 eax, dword ptr [esp + 0x60]
            //   498bce               | dec                 eax
            //   e8????????           |                     
            //   e9????????           |                     
            //   498bce               | mov                 ebx, edx

        $sequence_1 = { 8985e0040000 428d0407 41ffc0 8b1482 8bc3 480fafd6 4803d0 }
            // n = 7, score = 100
            //   8985e0040000         | mov                 cl, byte ptr [ecx + esi + 0x8dd90]
            //   428d0407             | dec                 eax
            //   41ffc0               | sub                 edx, eax
            //   8b1482               | mov                 eax, dword ptr [edx - 4]
            //   8bc3                 | dec                 eax
            //   480fafd6             | add                 edx, ecx
            //   4803d0               | movzx               ecx, byte ptr [edx]

        $sequence_2 = { 486385ec020000 488d0dfe50ffff 8b8481a8b40000 4803c1 ffe0 8b85ec020000 2d03400000 }
            // n = 7, score = 100
            //   486385ec020000       | mov                 dword ptr [ebp + 0x3c8], ecx
            //   488d0dfe50ffff       | dec                 esp
            //   8b8481a8b40000       | lea                 ecx, [0x21844]
            //   4803c1               | subsd               xmm1, xmm2
            //   ffe0                 | inc                 ecx
            //   8b85ec020000         | mulps               xmm1, xmmword ptr [ecx + eax*8]
            //   2d03400000           | movapd              xmm2, xmm1

        $sequence_3 = { 488d1dad050500 483bcb 740c e8???????? 48891d???????? b001 4883c420 }
            // n = 7, score = 100
            //   488d1dad050500       | je                  0x1361
            //   483bcb               | dec                 eax
            //   740c                 | lea                 eax, [0x78c3b]
            //   e8????????           |                     
            //   48891d????????       |                     
            //   b001                 | dec                 eax
            //   4883c420             | mov                 dword ptr [edx], eax

        $sequence_4 = { 740c 0fb703 4883c302 6685c0 75df 488d442440 88942433020000 }
            // n = 7, score = 100
            //   740c                 | cmp                 byte ptr [eax], 0x40
            //   0fb703               | je                  0xf3d
            //   4883c302             | mov                 dword ptr [ebp - 0x31], 5
            //   6685c0               | dec                 eax
            //   75df                 | lea                 eax, [0x6ddea]
            //   488d442440           | cmp                 al, 2
            //   88942433020000       | jne                 0xe55

        $sequence_5 = { 4885d2 0f8578ffffff 4883feff 7519 6645894c7bfe 8d4250 488b5c2430 }
            // n = 7, score = 100
            //   4885d2               | mov                 eax, 0xffffffff
            //   0f8578ffffff         | dec                 eax
            //   4883feff             | cmp                 dword ptr [ebp + 0x28], eax
            //   7519                 | je                  0x195d
            //   6645894c7bfe         | dec                 eax
            //   8d4250               | lea                 ebp, [ebx + 0x20]
            //   488b5c2430           | dec                 eax

        $sequence_6 = { eb04 44896320 488b4310 8a08 48ffc0 48894310 884b39 }
            // n = 7, score = 100
            //   eb04                 | dec                 eax
            //   44896320             | mov                 eax, dword ptr [esp + 0x98]
            //   488b4310             | dec                 eax
            //   8a08                 | mov                 dword ptr [esp + 0xa0], eax
            //   48ffc0               | dec                 esp
            //   48894310             | mov                 eax, dword ptr [esp + 0xc8]
            //   884b39               | dec                 eax

        $sequence_7 = { b8cdcccccc 41f7e0 c1ea03 8d0492 03c0 442bc0 0f84d0000000 }
            // n = 7, score = 100
            //   b8cdcccccc           | lea                 ecx, [0x29581]
            //   41f7e0               | xor                 ecx, ecx
            //   c1ea03               | dec                 esp
            //   8d0492               | lea                 eax, [0x29574]
            //   03c0                 | dec                 eax
            //   442bc0               | sub                 esp, 0x28
            //   0f84d0000000         | dec                 eax

        $sequence_8 = { 898584000000 488d0df6490800 e8???????? 488b8d68020000 488b09 48898df8090000 488bd0 }
            // n = 7, score = 100
            //   898584000000         | dec                 esp
            //   488d0df6490800       | mov                 eax, edx
            //   e8????????           |                     
            //   488b8d68020000       | mov                 dword ptr [ecx], edx
            //   488b09               | dec                 ecx
            //   48898df8090000       | shr                 eax, 0x20
            //   488bd0               | inc                 ebp

        $sequence_9 = { 4533c9 4489ada0040000 4c8d85a4040000 45892e bacc010000 e8???????? 32c0 }
            // n = 7, score = 100
            //   4533c9               | jmp                 0x13ce
            //   4489ada0040000       | dec                 eax
            //   4c8d85a4040000       | add                 ecx, 0x460
            //   45892e               | dec                 ebp
            //   bacc010000           | add                 esi, esi
            //   e8????????           |                     
            //   32c0                 | dec                 ebx

    condition:
        7 of them and filesize < 1483776
}
Download all Yara Rules