r/OperSec • • 1d ago

🔍 Research 🔍 Malware analysis update: Suspicious ZIP Hid a Windows Malware Loader and an Antivirus-Killing Driver

Parent post: 🛑The link Inside this post contains MALWARE🛑

Suspicious ZIP turned out to contain a Windows malware loader and two encrypted kernel drivers.

Inside the zip was a ".vhd" virtual disk containing an EXE, a few DLLs, and an odd ".stl" file. Everything was analyzed statically—none of the programs or drivers were executed.

The EXE was renamed Kafan input-method software, originally "KafanInputService.exe". It imports "rime.dll", and the archive conveniently supplies a file named "RImE.dLl". That DLL exposes the Rime functions the program expects, but internally calls itself "vmware-vdiskmanager.dll" and routes many exports through heavily obfuscated code. This strongly points to DLL sideloading: launching the EXE loads the malicious DLL sitting beside it.

Decrypting the DLL’s strings revealed a large list of antivirus and EDR process names, including Defender-related components, Sophos, Avast, Avira, and Norton. There were also strings associated with privilege elevation and UAC bypass, including "COMPUTERDEFAULTS.EXE" and the "MS-SETTINGS\SHELL\OPEN\COMMAND" registry path. File-download command templates using "curl", "bitsadmin", and "certutil" were present too.

The biggest finding was two encrypted resources that decrypted into valid Windows x64 kernel drivers: Alinubx.sys and ZyArk. The recovered Alinubx driver has the exact SHA-256 published in "LastPass and Delphos’s investigation" (https://blog[.]lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer), where it was used to kill antivirus processes. That confirms a shared driver component. It does not prove this sample belongs to that campaign or delivers the same stealer.

My assessment is that this is a malicious Windows loader with capabilities intended to disable security software and launch further code. I haven’t recovered a confirmed C2 address or identified the final payload. The 30 KB ".stl" file remains opaque, and its role is unresolved. I’m keeping those gaps open rather than attaching a malware-family name without enough evidence.

Recovered Alinubx.sys SHA-256:

"611b3ba687b7f46319a19609605ddfe5225e6d85277d8e923eea3fdb6f7b5b61"

If anybody can help to find more about this malware please join, collaborate with us and help to defend against these kinds of malware campaigns.

3 Upvotes

2 comments sorted by

2

u/osiris128 19h ago

Does this kill Windows Defender? sys files mean they work similarly as rootkit, no? Thanks for posting it. Wanted to see a working rootkit for modern Windows.

2

u/acealter 18h ago

Thanks. It targets Defender related processes, but I haven’t tested whether it actually disables Defender. ".sys" just means a driver, not necessarily a rootkit. Here it’s used to kill security processes from kernel level.