SYMBOLCOMMON_NAMEaka. SYNONYMS
win.unidentified_080 (Back to overview)

Unidentified 080

Actor(s): EMISSARY PANDA

VTCollection    

This Trojan is a full-featured RAT capable of executing common tasks such as command execution and downloading/uploading files. This is implemented through a couple dozen C++ classes such as CMFile, CMFile, CMProcess, TFileDownload, TDrive, TProcessInfo, TSock, etc. The first stage custom installer utilizes the same classes. The Trojan uses HTTP Server API to filter HTTPS packets at port 443 and parse commands.
It is also used by attackers to gather a target’s data, make lateral movements and create SOCKS tunnels to their C2 using the Earthworm tunneler.Given that the Trojan is an HTTPS server itself, the SOCKS tunnel is used for targets without an external IP, so the C2 is able to send commands.

References
2018-09-10 ⋅ Kaspersky Labs ⋅ GReAT
LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
Unidentified 080 APT27
Yara Rules
[TLP:WHITE] win_unidentified_080_auto (20260917 | Detects win.unidentified_080.)
rule win_unidentified_080_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.unidentified_080."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_080"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c7433090310210 ff15???????? c7433078310210 8bc3 c745fcffffffff e8???????? 8b4df4 }
            // n = 7, score = 100
            //   c7433090310210       | mov                 dword ptr [ebx + 0x30], 0x10023190
            //   ff15????????         |                     
            //   c7433078310210       | mov                 dword ptr [ebx + 0x30], 0x10023178
            //   8bc3                 | mov                 eax, ebx
            //   c745fcffffffff       | mov                 dword ptr [ebp - 4], 0xffffffff
            //   e8????????           |                     
            //   8b4df4               | mov                 ecx, dword ptr [ebp - 0xc]

        $sequence_1 = { 760f 53 8d75d8 e8???????? }
            // n = 4, score = 100
            //   760f                 | jbe                 0x11
            //   53                   | push                ebx
            //   8d75d8               | lea                 esi, [ebp - 0x28]
            //   e8????????           |                     

        $sequence_2 = { 33c0 8945f5 668945f9 8845fb 8b470c 53 2bc1 }
            // n = 7, score = 100
            //   33c0                 | xor                 eax, eax
            //   8945f5               | mov                 dword ptr [ebp - 0xb], eax
            //   668945f9             | mov                 word ptr [ebp - 7], ax
            //   8845fb               | mov                 byte ptr [ebp - 5], al
            //   8b470c               | mov                 eax, dword ptr [edi + 0xc]
            //   53                   | push                ebx
            //   2bc1                 | sub                 eax, ecx

        $sequence_3 = { e8???????? 83c404 894604 85c0 741c 8d0c38 0345e8 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   83c404               | add                 esp, 4
            //   894604               | mov                 dword ptr [esi + 4], eax
            //   85c0                 | test                eax, eax
            //   741c                 | je                  0x1e
            //   8d0c38               | lea                 ecx, [eax + edi]
            //   0345e8               | add                 eax, dword ptr [ebp - 0x18]

        $sequence_4 = { ff15???????? 85c0 7526 3bf7 7407 56 ff15???????? }
            // n = 7, score = 100
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   7526                 | jne                 0x28
            //   3bf7                 | cmp                 esi, edi
            //   7407                 | je                  9
            //   56                   | push                esi
            //   ff15????????         |                     

        $sequence_5 = { 8d5508 52 6a1f 50 ff15???????? b801000000 }
            // n = 6, score = 100
            //   8d5508               | lea                 edx, [ebp + 8]
            //   52                   | push                edx
            //   6a1f                 | push                0x1f
            //   50                   | push                eax
            //   ff15????????         |                     
            //   b801000000           | mov                 eax, 1

        $sequence_6 = { 6a00 6a00 50 51 6818242200 8d4dbc e8???????? }
            // n = 7, score = 100
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   50                   | push                eax
            //   51                   | push                ecx
            //   6818242200           | push                0x222418
            //   8d4dbc               | lea                 ecx, [ebp - 0x44]
            //   e8????????           |                     

        $sequence_7 = { 83f8ff 0f8463050000 be???????? 89b59cfdffff 89bdacfdffff b329 66c785a0fdffff2929 }
            // n = 7, score = 100
            //   83f8ff               | cmp                 eax, -1
            //   0f8463050000         | je                  0x569
            //   be????????           |                     
            //   89b59cfdffff         | mov                 dword ptr [ebp - 0x264], esi
            //   89bdacfdffff         | mov                 dword ptr [ebp - 0x254], edi
            //   b329                 | mov                 bl, 0x29
            //   66c785a0fdffff2929     | mov    word ptr [ebp - 0x260], 0x2929

        $sequence_8 = { 52 8d0470 50 e8???????? 8b8dbcf7ffff 83c40c 2bdf }
            // n = 7, score = 100
            //   52                   | push                edx
            //   8d0470               | lea                 eax, [eax + esi*2]
            //   50                   | push                eax
            //   e8????????           |                     
            //   8b8dbcf7ffff         | mov                 ecx, dword ptr [ebp - 0x844]
            //   83c40c               | add                 esp, 0xc
            //   2bdf                 | sub                 ebx, edi

        $sequence_9 = { 33c9 52 66894c780c 83c00c 53 50 8906 }
            // n = 7, score = 100
            //   33c9                 | xor                 ecx, ecx
            //   52                   | push                edx
            //   66894c780c           | mov                 word ptr [eax + edi*2 + 0xc], cx
            //   83c00c               | add                 eax, 0xc
            //   53                   | push                ebx
            //   50                   | push                eax
            //   8906                 | mov                 dword ptr [esi], eax

    condition:
        7 of them and filesize < 392192
}
Download all Yara Rules