TL;DR

Sample: ANY.RUN
Gulpix is a specialized backdoor for cyber espionage targeting corporate and government Windows systems. It is primarily distributed through targeted phishing using malicious documents that exploit vulnerabilities in Microsoft Office. The malware employs DLL side-loading technique via legitimate executable files for stealthy persistence and EDR bypass. The backdoor provides attackers with full remote control, including arbitrary command execution, file system management, and screenshots, using encrypted HTTP/HTTPS requests for C2 communication and exfiltration of sensitive data.
How to detect: Detection based on identifying specific artifacts of malware presence in the operating system: primarily, the presence in memory of a unique mutex whose name matches a regular expression pattern (32-character hexadecimal string with suffix b2e63bf56128101452b3fe22714547f2).
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2025-12-29 | TI | 2026-01-20 | 2 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"drivers" AND syncObjectName:"*b2e63bf56128101452b3fe22714547f2"
IOCs:
886a25ba77bd73fe4960404bc07edcf5a3708fc02c39beec26df5f14151841fbhttp://xcd.yycsl.tophttp://xcd.seaya.sitehttp://apps.game.qq.comhttp://sp1.baidu.comhttps://dns.alidns.comhttp://nru.yycsl.topMITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1574.002 | Hijack Execution Flow: DLL side-loading | Gulpix uses DLL side-loading by substituting a malicious library under the name of a legitimate dependency loaded by a signed trusted EXE. |
| T1027 | Obfuscated Files or Information | All strings, APIs, and Gulpix configuration are encrypted; RC4 and XOR are used to hide code and payload configuration in memory or resources. |
| T1218.011 | Signed Binary Proxy Execution: Rundll32 | Gulpix modules can be launched via rundll32.exe with encrypted payload and export specification. |
| T1055.012 | Process Injection: Process Hollowing | Gulpix injects code into legitimate processes via hollowing to mask activity. |
| T1005 | Data from Local System | Gulpix can steal documents, configuration files, and dump contents of removable drives. |
| T1056.001 | Input Capture: Keylogging | The malware includes a module for capturing keystrokes and recording user activity. |
| T1105 | Ingress Tool Transfer | Supports downloading and executing additional plugins and configurations from C2. |
| T1071.001 | Application Layer Protocol: Web Protocols | C2 communication uses HTTP/HTTPS, often on non-standard ports with custom headers. |

Sample: ANY.RUN
VVS Stealer is a Python-based infostealer actively sold on Telegram. The malware targets Discord users, browsers, and system data, hiding its logic with Pyarmor to complicate analysis and bypass traditional detections. It extracts Discord tokens and account data, as well as saved passwords, cookies, history, and autofill from popular browsers, then sends them to attackers via HTTP POST and webhook endpoints.
How to detect: Before sending to C2, VVS Stealer collects all stolen data into an archive admin_Vault.zip, whose location depends on the stealer’s launch directory.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2026-01-19 | News | 2026-01-19 | 3 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"\\admin_Vault.zip"
IOCs:
7a1554383345f31f3482ba3729c1126af7c1d9376abb07ad3ee189660c166a2bvvs[.]cymruptb.discord[.]com/api/webhooks/1360401843963826236/TkFvXfHFXrBIKT3EaqekJefvdvt39XTAxeOIWECeSrBbNLKDR5yPcn75uIqKEzdfs9o2MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1087 | Account Discovery | VVS Stealer analyzes local users and administrative accounts |
| T1056 | Input Capture | Captures passwords, logins, and other sensitive data |
| T1555 | Credentials from Password Stores | Targets password stores in browsers and applications |
| T1560 | Archive Collected Data | All data is packed into admin_Vault.zip before sending to C2 |
| T1041 | Exfiltration Over C2 Channel | Sends archives to attacker-controlled server |
| T1497 | Virtualization/Sandbox Evasion | Checks environment and execution conditions before data collection |
| T1027 | Obfuscated Files or Information | Uses packing and encryption to hide content |

Sample: ANY.RUN
Rustwater is a backdoor with RAT capabilities capable of stealing data. The implant is written in Rust and delivered via Word documents with macros and spear-phishing techniques.
How to detect: Detection through monitoring of anomalous command-line executions, particularly those related to the CertificationKit.ini file in ProgramData.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2026-01-14 | TI | 2026-01-20 | 0 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"cmd*C:\\ProgramData\\CertificationKit.ini"
IOCs:
76aad2a7fa265778520398411324522c57bfd7d2ff30a5cfe6460960491bc552f38a56b8dc0e8a581999621eef65ef497f0ac0d35e953bd94335926f00e9464f7523e53c979692f9eecff6ec760ac3df5b47f172114286e570b6bba3b2133f58e61b2ed360052a256b3c8761f09d185dad15c67595599da3e587c2c553e83108a2001892410e9f34ff0d02c8bc9e7c53b0bd10da58461e1e9eab26bdbf410c79c23bac59d70661bb9a99573cf098d668e9395a636dc6f6c20f92c41013c30be842ad0c70e997a268286654b792c7833fd7c6a2a6a80d9f30d3f462518036d04ce081bc408f73158c7338823f01455e4f5185a4365c8aad1d60d777e29166abbd3d1e43682c4d306e41127ca91993c7befd6db626ddbe3c1ee4b2cf44c0d2fb43ddc6e6c76ac325d89799a50dffd11ec69ed3b5341740619b8e595b8068220914MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1059.003 | Command and Scripting Interpreter: Windows Command Shell | Starts CMD.EXE for commands execution |
| T1012 | Query Registry | Checks different registries |
| T1082 | System Information Discovery | Gets information about the operating system and hardware |
| T1204 | User Execution: Malicious File | Execution of malicious lure file |
1) Malware continues to use predictable mutexes: Gulpix creates a mutex with fixed suffix b2e63bf56128101452b3fe22714547f2, which remains a reliable detection artifact despite attempts to hide other components via DLL side-loading.
2) Stealers often leave intermediate archives on disk: VVS Stealer collects all data into the file admin_Vault.zip before exfiltration, creating an easily detectable artifact in the infected machine’s file system.
3) Use of common directories for persistence: Rustwater places its files in C:\ProgramData and launches via cmd, generating easily trackable behavioral indicators.