SYMBOLCOMMON_NAMEaka. SYNONYMS
win.vyveva (Back to overview)

Vyveva RAT

Actor(s): Lazarus Group

VTCollection    

Vyveva is a remote access trojan that uses the Tor library for communication with C&C. Its use of fake TLS for camouflaging the network traffic is one of the typical Lazarus traits.

It uses a simple XOR for encryption of its configuration and network traffic.

It sends detailed information about the victim's environment, like computer name, user name, IP, code page, Windows version, architecture, and time zone.

It supports more than 20 commands that include operations on the victim’s filesystem, basic process management, command line execution, file exfiltration, and the download and memory execution of an additional DLL from the C&C (by calling the expected export SamIPromote). As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. The lowest index is 0x3, followed by 0x10, which goes incrementally up to 0x26. Also, it can monitor newly connected drives and the number of logged-on users.

It has MPRD.dll as the internal DLL name, and a single export SamIInitialize.

Vyveva RAT was used in an attack against a freight logistics company in South Africa in June 2020.

References
2021-04-08 ⋅ ESET Research ⋅ Filip Jurčacko
(Are you) afreight of the dark? Watch out for Vyveva, new Lazarus backdoor
Vyveva RAT
Yara Rules
[TLP:WHITE] win_vyveva_auto (20260917 | Detects win.vyveva.)
rule win_vyveva_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.vyveva."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vyveva"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 83ee50 85ff 75ce 56 58 5f 5e }
            // n = 7, score = 100
            //   83ee50               | sub                 esi, 0x50
            //   85ff                 | test                edi, edi
            //   75ce                 | jne                 0xffffffd0
            //   56                   | push                esi
            //   58                   | pop                 eax
            //   5f                   | pop                 edi
            //   5e                   | pop                 esi

        $sequence_1 = { 46 c784240401000000000000 01b42404010000 83c602 89b42408010000 56 5d }
            // n = 7, score = 100
            //   46                   | inc                 esi
            //   c784240401000000000000     | mov    dword ptr [esp + 0x104], 0
            //   01b42404010000       | add                 dword ptr [esp + 0x104], esi
            //   83c602               | add                 esi, 2
            //   89b42408010000       | mov                 dword ptr [esp + 0x108], esi
            //   56                   | push                esi
            //   5d                   | pop                 ebp

        $sequence_2 = { 57 89cf 59 89cf 5f 51 5f }
            // n = 7, score = 100
            //   57                   | push                edi
            //   89cf                 | mov                 edi, ecx
            //   59                   | pop                 ecx
            //   89cf                 | mov                 edi, ecx
            //   5f                   | pop                 edi
            //   51                   | push                ecx
            //   5f                   | pop                 edi

        $sequence_3 = { ff7304 59 8b742428 c7442420ffffffff ff7104 5a 8d4c2414 }
            // n = 7, score = 100
            //   ff7304               | push                dword ptr [ebx + 4]
            //   59                   | pop                 ecx
            //   8b742428             | mov                 esi, dword ptr [esp + 0x28]
            //   c7442420ffffffff     | mov                 dword ptr [esp + 0x20], 0xffffffff
            //   ff7104               | push                dword ptr [ecx + 4]
            //   5a                   | pop                 edx
            //   8d4c2414             | lea                 ecx, [esp + 0x14]

        $sequence_4 = { 83c404 ffd0 8d8424b40a0000 8d8c249c060000 50 51 6a43 }
            // n = 7, score = 100
            //   83c404               | add                 esp, 4
            //   ffd0                 | call                eax
            //   8d8424b40a0000       | lea                 eax, [esp + 0xab4]
            //   8d8c249c060000       | lea                 ecx, [esp + 0x69c]
            //   50                   | push                eax
            //   51                   | push                ecx
            //   6a43                 | push                0x43

        $sequence_5 = { 8f02 885a04 e8???????? 99 b905000000 f7f9 }
            // n = 6, score = 100
            //   8f02                 | pop                 dword ptr [edx]
            //   885a04               | mov                 byte ptr [edx + 4], bl
            //   e8????????           |                     
            //   99                   | cdq                 
            //   b905000000           | mov                 ecx, 5
            //   f7f9                 | idiv                ecx

        $sequence_6 = { 0f8618020000 33c9 034d04 2bc7 50 8d1439 52 }
            // n = 7, score = 100
            //   0f8618020000         | jbe                 0x21e
            //   33c9                 | xor                 ecx, ecx
            //   034d04               | add                 ecx, dword ptr [ebp + 4]
            //   2bc7                 | sub                 eax, edi
            //   50                   | push                eax
            //   8d1439               | lea                 edx, [ecx + edi]
            //   52                   | push                edx

        $sequence_7 = { 8d7c3b60 83ef60 49 75ef 8b549424 33db }
            // n = 6, score = 100
            //   8d7c3b60             | lea                 edi, [ebx + edi + 0x60]
            //   83ef60               | sub                 edi, 0x60
            //   49                   | dec                 ecx
            //   75ef                 | jne                 0xfffffff1
            //   8b549424             | mov                 edx, dword ptr [esp + edx*4 + 0x24]
            //   33db                 | xor                 ebx, ebx

        $sequence_8 = { c74424fc00000000 014424fc 83ec04 2bc6 58 89742428 }
            // n = 6, score = 100
            //   c74424fc00000000     | mov                 dword ptr [esp - 4], 0
            //   014424fc             | add                 dword ptr [esp - 4], eax
            //   83ec04               | sub                 esp, 4
            //   2bc6                 | sub                 eax, esi
            //   58                   | pop                 eax
            //   89742428             | mov                 dword ptr [esp + 0x28], esi

        $sequence_9 = { 03f9 59 39f9 7408 c7c100000000 01f9 59 }
            // n = 7, score = 100
            //   03f9                 | add                 edi, ecx
            //   59                   | pop                 ecx
            //   39f9                 | cmp                 ecx, edi
            //   7408                 | je                  0xa
            //   c7c100000000         | mov                 ecx, 0
            //   01f9                 | add                 ecx, edi
            //   59                   | pop                 ecx

    condition:
        7 of them and filesize < 360448
}
Download all Yara Rules