TL;DR

  • Gulpix (Windows backdoor): A specialized backdoor used for cyber espionage, distributed via spear-phishing campaigns with malicious Office documents. It leverages DLL side-loading and creates a unique mutex with the fixed suffix b2e63bf56128101452b3fe22714547f2.
  • VVS Stealer (Python infostealer): An infostealer sold via Telegram that targets Discord tokens and browser data. It uses Pyarmor obfuscation and packages stolen data into an admin_Vault.zip archive prior to exfiltration.
  • Rustwater (Rust backdoor/RAT): A Rust-based backdoor with RAT and data-theft capabilities, delivered through Word documents containing macros. Detection is based on anomalous command lines involving CertificationKit.ini.

1) Gulpix (Windows)

Sample: ANY.RUN

Gulpix is a specialized backdoor for cyber espionage targeting corporate and government Windows systems. It is primarily distributed through targeted phishing using malicious documents that exploit vulnerabilities in Microsoft Office. The malware employs DLL side-loading technique via legitimate executable files for stealthy persistence and EDR bypass. The backdoor provides attackers with full remote control, including arbitrary command execution, file system management, and screenshots, using encrypted HTTP/HTTPS requests for C2 communication and exfiltration of sensitive data.

How to detect: Detection based on identifying specific artifacts of malware presence in the operating system: primarily, the presence in memory of a unique mutex whose name matches a regular expression pattern (32-character hexadecimal string with suffix b2e63bf56128101452b3fe22714547f2).

Key facts:

  • Stealth persistence architecture based on DLL side-loading.
  • Dynamic creation of unique mutexes with fixed suffix.
  • Direct WinAPI calls, obfuscated launch paths in %TEMP%/%APPDATA%.
  • Custom encryption of HTTP/HTTPS traffic, self-protection features, and environment checks.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2025-12-29 TI 2026-01-20 2

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: filePath:"drivers" AND syncObjectName:"*b2e63bf56128101452b3fe22714547f2"

IOCs:

  • SHA256: 886a25ba77bd73fe4960404bc07edcf5a3708fc02c39beec26df5f14151841fb
  • URL: http://xcd.yycsl.top
  • URL: http://xcd.seaya.site
  • URL: http://apps.game.qq.com
  • URL: http://sp1.baidu.com
  • URL: https://dns.alidns.com
  • URL: http://nru.yycsl.top

MITRE:

Technique ID Technique Name Evidence
T1574.002 Hijack Execution Flow: DLL side-loading Gulpix uses DLL side-loading by substituting a malicious library under the name of a legitimate dependency loaded by a signed trusted EXE.
T1027 Obfuscated Files or Information All strings, APIs, and Gulpix configuration are encrypted; RC4 and XOR are used to hide code and payload configuration in memory or resources.
T1218.011 Signed Binary Proxy Execution: Rundll32 Gulpix modules can be launched via rundll32.exe with encrypted payload and export specification.
T1055.012 Process Injection: Process Hollowing Gulpix injects code into legitimate processes via hollowing to mask activity.
T1005 Data from Local System Gulpix can steal documents, configuration files, and dump contents of removable drives.
T1056.001 Input Capture: Keylogging The malware includes a module for capturing keystrokes and recording user activity.
T1105 Ingress Tool Transfer Supports downloading and executing additional plugins and configurations from C2.
T1071.001 Application Layer Protocol: Web Protocols C2 communication uses HTTP/HTTPS, often on non-standard ports with custom headers.

2) VVS Stealer (Windows/Python)

Sample: ANY.RUN

VVS Stealer is a Python-based infostealer actively sold on Telegram. The malware targets Discord users, browsers, and system data, hiding its logic with Pyarmor to complicate analysis and bypass traditional detections. It extracts Discord tokens and account data, as well as saved passwords, cookies, history, and autofill from popular browsers, then sends them to attackers via HTTP POST and webhook endpoints.

How to detect: Before sending to C2, VVS Stealer collects all stolen data into an archive admin_Vault.zip, whose location depends on the stealer’s launch directory.

Key facts:

  • Pyarmor obfuscation increases difficulty of static analysis.
  • Displays fake error message to mask activity.
  • Intercepts active sessions via injected JS payloads in Discord.
  • Targets Discord credentials, tokens, Nitro subscriptions, email, phone, friends, and servers.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2026-01-19 News 2026-01-19 3

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: filePath:"\\admin_Vault.zip"

IOCs:

  • SHA256: 7a1554383345f31f3482ba3729c1126af7c1d9376abb07ad3ee189660c166a2b
  • C2 panel: vvs[.]cymru
  • Discord webhook: ptb.discord[.]com/api/webhooks/1360401843963826236/TkFvXfHFXrBIKT3EaqekJefvdvt39XTAxeOIWECeSrBbNLKDR5yPcn75uIqKEzdfs9o2

MITRE:

Technique ID Technique Name Evidence
T1087 Account Discovery VVS Stealer analyzes local users and administrative accounts
T1056 Input Capture Captures passwords, logins, and other sensitive data
T1555 Credentials from Password Stores Targets password stores in browsers and applications
T1560 Archive Collected Data All data is packed into admin_Vault.zip before sending to C2
T1041 Exfiltration Over C2 Channel Sends archives to attacker-controlled server
T1497 Virtualization/Sandbox Evasion Checks environment and execution conditions before data collection
T1027 Obfuscated Files or Information Uses packing and encryption to hide content

3) Rustwater (Windows/Rust)

Sample: ANY.RUN

Rustwater is a backdoor with RAT capabilities capable of stealing data. The implant is written in Rust and delivered via Word documents with macros and spear-phishing techniques.

How to detect: Detection through monitoring of anomalous command-line executions, particularly those related to the CertificationKit.ini file in ProgramData.

Key facts:

  • Written in Rust.
  • Delivered via malicious Word documents with macros.
  • Command execution, system information collection, registry operations.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2026-01-14 TI 2026-01-20 0

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: commandLine:"cmd*C:\\ProgramData\\CertificationKit.ini"

IOCs:

  • SHA256: 76aad2a7fa265778520398411324522c57bfd7d2ff30a5cfe6460960491bc552
  • SHA256: f38a56b8dc0e8a581999621eef65ef497f0ac0d35e953bd94335926f00e9464f
  • SHA256: 7523e53c979692f9eecff6ec760ac3df5b47f172114286e570b6bba3b2133f58
  • SHA256: e61b2ed360052a256b3c8761f09d185dad15c67595599da3e587c2c553e83108
  • SHA256: a2001892410e9f34ff0d02c8bc9e7c53b0bd10da58461e1e9eab26bdbf410c79
  • SHA256: c23bac59d70661bb9a99573cf098d668e9395a636dc6f6c20f92c41013c30be8
  • SHA256: 42ad0c70e997a268286654b792c7833fd7c6a2a6a80d9f30d3f462518036d04c
  • SHA256: e081bc408f73158c7338823f01455e4f5185a4365c8aad1d60d777e29166abbd
  • SHA256: 3d1e43682c4d306e41127ca91993c7befd6db626ddbe3c1ee4b2cf44c0d2fb43
  • SHA256: ddc6e6c76ac325d89799a50dffd11ec69ed3b5341740619b8e595b8068220914

MITRE:

Technique ID Technique Name Evidence
T1059.003 Command and Scripting Interpreter: Windows Command Shell Starts CMD.EXE for commands execution
T1012 Query Registry Checks different registries
T1082 System Information Discovery Gets information about the operating system and hardware
T1204 User Execution: Malicious File Execution of malicious lure file

Conclusion

1) Malware continues to use predictable mutexes: Gulpix creates a mutex with fixed suffix b2e63bf56128101452b3fe22714547f2, which remains a reliable detection artifact despite attempts to hide other components via DLL side-loading.

2) Stealers often leave intermediate archives on disk: VVS Stealer collects all data into the file admin_Vault.zip before exfiltration, creating an easily detectable artifact in the infected machine’s file system.

3) Use of common directories for persistence: Rustwater places its files in C:\ProgramData and launches via cmd, generating easily trackable behavioral indicators.