Execution Flow Chart | Image: K7 Labs
Researchers at K7 Labs have discovered a highly obfuscated Python-based malware using multi-layer encoding, disguised archive formats, and stealthy process injection to establish persistent command-and-control (C2) communications on infected systems. The campaign appears carefully engineered to evade both user suspicion and traditional security controls by blending legitimate-looking components with deeply nested payload transformations.
The attack chain begins with a PE dropper decrypting its embedded payload at runtime, reconstructing a malicious batch script (config.bat) and writing it to disk. The malware follows a multi-step unpacking flow culminating in Python execution.
K7 Labs explains, βThe infection chain starts with a PE dropper containing a runtime decryption routineβ¦ writing the reconstructed payload to disk via WriteFile.β
The batch script then downloads what appears to be a harmless PNG fileβbut this βimageβ is actually a RAR archive disguised with a .png extension:
βAlthough the downloaded file has a .png extension, itβs actually a RAR archive β this is a simple and well used trick as users and security filters treat .png files as harmless.β
Once extracted, the malware reveals more deception:
- AsusMouseDriver.sys β actually a password-protected RAR
- Interput.json β renamed to Install.bat at runtime
- Inx β a legitimate WinRAR helper executable used to unpack the hidden archive
After unpacking, the script builds a fake Windows directory:
βThe directory named WindowsSecurityA now holds: a file named ntoskrnl.exe (pretending to be a Windows kernel file, but actually a bundled Python runtime)β¦ [and] the main obfuscated Python payload.β
The loader then executes this counterfeit ntoskrnl.exe with two argumentsβdcconsbot and dcaatβwhich serve as keys for triggering the malwareβs multilayer de-obfuscation sequence. These arguments are passed directly to the Python interpreter.
K7 Labs notes that the actual malicious logic is buried beneath several decoding and decompression layers: βThe unpacking process uses layered transformations: Base64 β BZ2 β Zlib β marshal.loads.β
Most of the resulting 65 MB blob is meaningless filler: βOnly a small portion near the end contains the valid marshalled Python bytecode.β This final .pyc payload is executed directly in memory.
Once unpacked, the payload immediately performs process injection into cvtres.exe, a legitimate Microsoft utility. This gives the malware two powerful advantages:
- βStealth: Security tools often trust signed Microsoft binariesβ¦ allowing malicious activity to look as if coming from a legitimate process.β
- βPersistence: Even if the loader process terminates, the injected process remains alive and continues C2 communication.β
Network analysis revealed that the injected .NET moduleβdownloaded from the attackerβs server at runtimeβestablishes encrypted TCP communications with the C2 infrastructure.
K7 Labs notes: βThis continuous, bidirectional, encrypted traffic pattern is characteristic of a remote-access trojan (RAT).β
The RAT functionality includes:
- Command execution
- File transfer
- Reconnaissance
- Persistent remote control
K7 Labs summarizes the entire operation concisely: βThe sample has several features: multi-layer encoding, masquerading of archive types, and bundling of a Python runtime with a signed/legitimate-looking executable name.β
Related Posts:
- APT29’s Espionage Campaign Exploits WinRAR Flaw, Targets Embassies
- TA397 Leverages Sophisticated Spearphishing Techniques to Deploy Malware in Defense Sector
- Sophisticated Phishing Campaign Uses Multi-Layered Tactics to Deliver Malware
- Unmasking Kimsuky’s Latest Tactics: A Deep Dive into Malicious Scripts and Payloads
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!