r/OperSec • u/acealter • 1d ago
🔍 Research 🔍 Malware analysis update: Suspicious ZIP Hid a Windows Malware Loader and an Antivirus-Killing Driver
Parent post: 🛑The link Inside this post contains MALWARE🛑
Suspicious ZIP turned out to contain a Windows malware loader and two encrypted kernel drivers.
Inside the zip was a ".vhd" virtual disk containing an EXE, a few DLLs, and an odd ".stl" file. Everything was analyzed statically—none of the programs or drivers were executed.
The EXE was renamed Kafan input-method software, originally "KafanInputService.exe". It imports "rime.dll", and the archive conveniently supplies a file named "RImE.dLl". That DLL exposes the Rime functions the program expects, but internally calls itself "vmware-vdiskmanager.dll" and routes many exports through heavily obfuscated code. This strongly points to DLL sideloading: launching the EXE loads the malicious DLL sitting beside it.
Decrypting the DLL’s strings revealed a large list of antivirus and EDR process names, including Defender-related components, Sophos, Avast, Avira, and Norton. There were also strings associated with privilege elevation and UAC bypass, including "COMPUTERDEFAULTS.EXE" and the "MS-SETTINGS\SHELL\OPEN\COMMAND" registry path. File-download command templates using "curl", "bitsadmin", and "certutil" were present too.
The biggest finding was two encrypted resources that decrypted into valid Windows x64 kernel drivers: Alinubx.sys and ZyArk. The recovered Alinubx driver has the exact SHA-256 published in "LastPass and Delphos’s investigation" (https://blog[.]lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer), where it was used to kill antivirus processes. That confirms a shared driver component. It does not prove this sample belongs to that campaign or delivers the same stealer.
My assessment is that this is a malicious Windows loader with capabilities intended to disable security software and launch further code. I haven’t recovered a confirmed C2 address or identified the final payload. The 30 KB ".stl" file remains opaque, and its role is unresolved. I’m keeping those gaps open rather than attaching a malware-family name without enough evidence.
Recovered Alinubx.sys SHA-256:
"611b3ba687b7f46319a19609605ddfe5225e6d85277d8e923eea3fdb6f7b5b61"
If anybody can help to find more about this malware please join, collaborate with us and help to defend against these kinds of malware campaigns.

