[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Pythons and Unicorns and Hancitor...Oh My! Decoding Binaries Through Emulation

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 11 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Jeff White](https://unit42.paloaltonetworks.com/author/jeff-white/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 30, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [Scam](https://unit42.paloaltonetworks.com/tag/scam/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation/?pdf=download&lg=en&_wpnonce=7faf0ddf08 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation/?pdf=print&lg=en&_wpnonce=7faf0ddf08 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Pythons%20and%20Unicorns%20and%20Hancitor…Oh%20My!%20Decoding%20Binaries%20Through%20Emulation&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation%2F&title=Pythons%20and%20Unicorns%20and%20Hancitor…Oh%20My!%20Decoding%20Binaries%20Through%20Emulation "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation%2F&text=Pythons%20and%20Unicorns%20and%20Hancitor…Oh%20My!%20Decoding%20Binaries%20Through%20Emulation "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Pythons%20and%20Unicorns%20and%20Hancitor…Oh%20My!%20Decoding%20Binaries%20Through%20Emulation%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-pythons-and-unicorns-and-hancitoroh-my-decoding-binaries-through-emulation%2F "Share in Mastodon")
  This blog post is a continuation of my previous post, [VB Dropper and Shellcode for Hancitor Reveal New Techniques Behind Uptick](https://blog.paloaltonetworks.com/2016/08/unit42-vb-dropper-and-shellcode-for-hancitor-reveal-new-techniques-behind-uptick/), where we analyzed a new Visual Basic (VB) macro dropper and the accompanying shellcode. In the last post, we left off with having successfully identified where the shellcode carved out and decoded a binary from the Microsoft Word document.

Often when analysts are faced with an embedded payload for which they want to write a decoder, they simply re-write the assembly algorithm in their language of choice and process the file. The complexity of these algorithms varies when attempting to translate from machine code to a higher-level language. It can be quite frustrating at times, depending on the amount of coffee you've had and complexity of the algorithms.

In this post, I'll show how we can use an attacker's own decoding algorithm combined with CPU emulation to decode or decrypt payloads fairly easily by simply reusing the assembly in front of us. Specifically, I'll be focusing on using the [Unicorn Engine](https://www.unicorn-engine.org/) module in Python to run the attacker's decoding functions within an emulated environment to extract our encoded payloads. Our end goal is to identify the command and control (C2) servers being used by the final Hancitor payload by running our Python script against the Microsoft Word document.

Now, you may ask, why even worry about this to begin with? In the last post we just let the program run and the payload was written to disk for easy retrieval, so why bother? The main answer to that is bulk-analysis automation. If we can write a program that we can point at a directory full of documents, then we can quickly extract embedded payloads for C2 extraction and parsing to form a more holistic view of what we're dealing with. An example of such bulk analysis was witnessed earlier this year in July when we [looked at a large sample set of LuminosityLink malware samples](https://blog.paloaltonetworks.com/2016/07/unit42-investigating-the-luminositylink-remote-access-trojan-configuration/).

### Decoding Routines

As a reminder, in the last blog post we were working with the following sample:

03aef51be133425a0e5978ab2529890854ecf1b98a7cf8289c142a62de7acd1a

We'll continue where we left off after identifying the decoding routine, as seen in figure 1. The function at loc\_B92 added 0x3 to each byte and uses 0x13 to XOR the result. Once every byte in the embedded binary has been processed, it pushes the location of the embedded binary to the stack and calls function sub\_827.

[![Hancitor\_unicorn\_1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_1.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_1.png)

*Figure 1 Start of decoding routine*

Without going too far into detail on the decoding routine, know that there are five parts to it, and that each one manipulates the bytes in some way before the overall function ends and our payload is decoded.

[![Hancitor\_unicorn\_2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_2-500x193.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_2.png)

*Figure 2 Proximity view of decoding functions in IDA*

What we're effectively going to do is copy the bytes from sub\_8A6, sub\_827, sub\_7E7, sub\_7CA, and sub\_7D7. These are the core functions that handle all of the decoding. In addition to this, we'll need our embedded payload, which can be located in the Word document through the magic header of "POLA" as discussed in the previous blog.

Once we have the copied bytes, we'll setup our emulation environment, adjust our assembly, and run our own shellcode to retrieve the payload. In the context of this blog, I'm just going to refer to the x86 instructions as shellcode to keep things straightforward.

Starting with offset 0xB92, we'll copy the bytes for the two blocks, ending just after our call since the payload will be decoded by that point.

[![Hancitor\_unicorn\_3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_3-500x189.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_3.png)

*Figure 3 Decoding function and associated bytes*

Next we'll copy the bytes from sub\_827, which are all of the bytes from offset 0x827 to 0x8A5.

[![Hancitor\_unicorn\_4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_4-500x145.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_4.png)

*Figure 4 Additional decoding functions and associated bytes*

Last, we'll collect the bytes from the three smaller functions. If you note their location, you can see they are contiguous. Keeping the bytes in order is convenient but not necessary. If they don't line up, you'll simply need to adjust the operands for the calls or jumps so that they go where they should.

[![Hancitor\_unicorn\_5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_5-500x226.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_5.png)

*Figure 5 Additional decoding functions and associated bytes*

Once all of the bytes have been saved, we can write them to a file and open it up in a disassembler to see what issues we need to correct, if any.

# sub\_8A6 sc = b'\\x8A\\x04\\x0F\\x04\\x03\\x34\\x13\\x88\\x04\\x0F\\x41\\x81\\xF9\\xAC\\x3A\\x01\\x 00\\x72\\xED\\x57\\xE8\\x7C\\xFC\\xFF\\xFF\\x83\\x7D\\xFC\\x01' \# sub\_7CA sc += b'\\x6B\\xC0\\x06\\x99\\x83\\xE2\\x07\\x03\\xC2\\xC1\\xF8\\x03\\xC3' \# sub\_7D7 sc += b'\\x6B\\xC0\\x06\\x25\\x07\\x00\\x00\\x80\\x79\\x05\\x48\\x83\\xC8\\xF8\\x40\\xC3' \<em\>\# sub\_7E7\</em\> sc += b'\\x8D\\x48\\xBF\\x80\\xF9\\x19\\x77\\x07\\x0F\\xBE\\xC0\\x83\\xE8\\x41\\xC3\\x8D\\x 48\\x9F\\x80\\xF9\\x19\\x77\\x07\\x0F\\xBE\\xC0\\x83\\xE8\\x47\\xC3\\x8D\\x48\\xD0\\x 80xF9\\x09\\x77\\x07\\x0F\\xBE\\xC0\\x83\\xC0\\x04\\xC3\\x3C\\x2B\\x75\\x04\\x6A\\x 3E\\x58\\xC3\\x3C\\x2F\\x75\\x04\\x6A\\x3F\\x58\\xC3\\x33\\xC0\\xC3' \# sub\_827 sc += b'\\x55\\x8B\\xEC\\x51\\x51\\x8B\\x45\\x08\\x83\\x65\\xFC\\x00\\x89\\x45\\xF8\\x8A\\x 00\\x84\\xC0\\x74\\x68\\x53\\x56\\x57\\xE8\\xA3\\xFF\\xFF\\xFF\\x8B\\xD8\\x8B\\x45\\x FC\\xE8\\x7C\\xFF\\xFF\\xFF\\x8B\\x4D\\xF8\\x8D\\x14\\x08\\x8B\\x45\\xFC\\xE8\\x7B\\x FF\\xFF\\xFF\\x8B\\xF8\\x8B\\xF0\\xF7\\xDE\\x8D\\x4E\\x08\\xB0\\x01\\xD2\\xE0\\xFE\\x C8\\xF6\\xD0\\x20\\x02\\x83\\xFF\\x03\\x7D\\x09\\x8D\\x4E\\x02\\xD2\\xE3\\x08\\x1A\\x EB\\x15\\x8D\\x4F\\xFE\\x8B\\xC3\\xD3\\xF8\\x8D\\x4E\\x0A\\xD2\\xE3\\x08\\x02\\xC6\\x 42\\x01\\x00\\x08\\x5A\\x01\\xFF\\x45\\x08\\x8B\\x45\\x08\\x8A\\x00\\xFF\\x45\\xFC\\x 84\\xC0\\x75\\x9E\\x5F\\x5E\\x5B\\xC9\\xC3'

|----------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 | # sub\_8A6 sc = b'\\x8A\\x04\\x0F\\x04\\x03\\x34\\x13\\x88\\x04\\x0F\\x41\\x81\\xF9\\xAC\\x3A\\x01\\x 00\\x72\\xED\\x57\\xE8\\x7C\\xFC\\xFF\\xFF\\x83\\x7D\\xFC\\x01' # sub\_7CA sc += b'\\x6B\\xC0\\x06\\x99\\x83\\xE2\\x07\\x03\\xC2\\xC1\\xF8\\x03\\xC3' # sub\_7D7 sc += b'\\x6B\\xC0\\x06\\x25\\x07\\x00\\x00\\x80\\x79\\x05\\x48\\x83\\xC8\\xF8\\x40\\xC3' \<em\># sub\_7E7\</em\> sc += b'\\x8D\\x48\\xBF\\x80\\xF9\\x19\\x77\\x07\\x0F\\xBE\\xC0\\x83\\xE8\\x41\\xC3\\x8D\\x 48\\x9F\\x80\\xF9\\x19\\x77\\x07\\x0F\\xBE\\xC0\\x83\\xE8\\x47\\xC3\\x8D\\x48\\xD0\\x 80xF9\\x09\\x77\\x07\\x0F\\xBE\\xC0\\x83\\xC0\\x04\\xC3\\x3C\\x2B\\x75\\x04\\x6A\\x 3E\\x58\\xC3\\x3C\\x2F\\x75\\x04\\x6A\\x3F\\x58\\xC3\\x33\\xC0\\xC3' # sub\_827 sc += b'\\x55\\x8B\\xEC\\x51\\x51\\x8B\\x45\\x08\\x83\\x65\\xFC\\x00\\x89\\x45\\xF8\\x8A\\x 00\\x84\\xC0\\x74\\x68\\x53\\x56\\x57\\xE8\\xA3\\xFF\\xFF\\xFF\\x8B\\xD8\\x8B\\x45\\x FC\\xE8\\x7C\\xFF\\xFF\\xFF\\x8B\\x4D\\xF8\\x8D\\x14\\x08\\x8B\\x45\\xFC\\xE8\\x7B\\x FF\\xFF\\xFF\\x8B\\xF8\\x8B\\xF0\\xF7\\xDE\\x8D\\x4E\\x08\\xB0\\x01\\xD2\\xE0\\xFE\\x C8\\xF6\\xD0\\x20\\x02\\x83\\xFF\\x03\\x7D\\x09\\x8D\\x4E\\x02\\xD2\\xE3\\x08\\x1A\\x EB\\x15\\x8D\\x4F\\xFE\\x8B\\xC3\\xD3\\xF8\\x8D\\x4E\\x0A\\xD2\\xE3\\x08\\x02\\xC6\\x 42\\x01\\x00\\x08\\x5A\\x01\\xFF\\x45\\x08\\x8B\\x45\\x08\\x8A\\x00\\xFF\\x45\\xFC\\x 84\\xC0\\x75\\x9E\\x5F\\x5E\\x5B\\xC9\\xC3' |

Looking at our shellcode, only one major issue appears, which is the initial call to the decoding function being at a different address.

[![Hancitor\_unicorn\_6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_6-500x277.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_6.png)

*Figure 6 Broken call within shellcode*

As we want to call to our previous function sub\_827, which is at the end of our shellcode, we can adjust this call to point to the start of that function. Looking at our code in a hex editor, the start of the function is exactly 97 bytes (0x61) into our shellcode, so we can change the instruction 0xE87CFCFFFF to 0xE861000000.

[![Hancitor\_unicorn\_7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_7-500x96.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_7.png)

*Figure 7 Correcting the previously broken call*

Next, we can validate our change worked as expected within the disassembler and that our functions are now all correctly linked.

[![Hancitor\_unicorn\_8](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_8-500x130.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_8.png)

*Figure 8 Validating correction of call*

### Embedded Payload

We know that our embedded payload address is located on the EDI register that gets pushed onto the stack through our previous dynamic analysis. For the initial validation of this method, we'll go ahead and manually copy the bytes, starting with the magic header of "POLA" and a size of 0x13AAAC bytes, to our Python script. At the end of the blog, I'll include a full script that will automatically extract this binary from the Word Document.

# POLA 0x504F4C41 encoded\_binary = b'\\x50\\x4F\\x4C\\x41\\x08\\x00\\xFF\\xFF\\xAC\\x3A\\x01\[truncated\]'

|-------|------------------------------------------------------------------------------------------------------------|
| 1 2 3 | # POLA 0x504F4C41 encoded\_binary = b'\\x50\\x4F\\x4C\\x41\\x08\\x00\\xFF\\xFF\\xAC\\x3A\\x01\[truncated\]' |

### Enter the Unicorn

As we now have all of the data we need to decode the binary, the last step for this part is to build the emulation environment for our code to run on. To accomplish this, I'll use the open-source [Unicorn Engine](https://www.unicorn-engine.org/).

The first thing we'll want to do is assign the address space we'll be working within, along with initializing Unicorn for the architecture we want to emulate (x86), and map some memory to use. Next we'll write our shellcode and encoded binary to our memory space and initialize some values. Finally, we'll output the decrypted data to STDOUT.  
ADDRESS = 0x1000000 mu = Uc(UC\_ARCH\_X86, UC\_MODE\_32) mu.mem\_map(ADDRESS, 4 \* 1024 \* 1024) # Write code to memory mu.mem\_write(ADDRESS, X86\_CODE32) # Start of encoded data + offset to binary, pushed to Stack at start mu.reg\_write(UC\_X86\_REG\_EDI, 0x10000F9 + 0x0C) # Initialize ECX counter to 0 mu.reg\_write(UC\_X86\_REG\_ECX, 0x0) # Initialize Stack for functions mu.reg\_write(UC\_X86\_REG\_ESP, 0x1300000) print "Encrypt: %s" % mu.mem\_read(0x10000F9,150) mu.emu\_start(ADDRESS, ADDRESS + len(X86\_CODE32)) print "Decrypt: %s" % mu.mem\_read(0x10000F9,150)

|-------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | ADDRESS = 0x1000000 mu = Uc(UC\_ARCH\_X86, UC\_MODE\_32) mu.mem\_map(ADDRESS, 4 \* 1024 \* 1024) # Write code to memory mu.mem\_write(ADDRESS, X86\_CODE32) # Start of encoded data + offset to binary, pushed to Stack at start mu.reg\_write(UC\_X86\_REG\_EDI, 0x10000F9 + 0x0C) # Initialize ECX counter to 0 mu.reg\_write(UC\_X86\_REG\_ECX, 0x0) # Initialize Stack for functions mu.reg\_write(UC\_X86\_REG\_ESP, 0x1300000) print "Encrypt: %s" % mu.mem\_read(0x10000F9,150) mu.emu\_start(ADDRESS, ADDRESS + len(X86\_CODE32)) print "Decrypt: %s" % mu.mem\_read(0x10000F9,150) |

[![Hancitor\_unicorn\_9](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_9-500x50.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_9.png)

*Figure 9 Successful decoding*

Success! We can write that section of memory to a file and see what we have.  
f = open("demo.exe", "w") f.write(mu.mem\_read(0x10000F9 + 0x0C, 0x13AAC)) f.close()

|-------|-------------------------------------------------------------------------------------|
| 1 2 3 | f = open("demo.exe", "w") f.write(mu.mem\_read(0x10000F9 + 0x0C, 0x13AAC)) f.close() |

[![Hancitor\_unicorn\_10](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_10.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_10.png)

*Figure 10 Decoded binary properties*

Unfortunately we find ourselves with a packed binary that may have our actual Hancitor sample, so we'll need to try and decode yet another payload.

[![Hancitor\_unicorn\_11](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_11-500x218.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_11.png)

### Attack of the Binaries

This binary has a fair amount of functions and code, but very early on we see the binary lookup the address for the same API we discussed in our earlier blog post, RtlMoveMemory(), and then copy what we presume is our encoded payload.

[![Hancitor\_unicorn\_12](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_12-500x276.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_12.png)

*Figure 11 RtlMoveMemory() being called*

[![Hancitor\_unicorn\_13](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_13-500x145.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_13.png)

*Figure 12 Encoded payload*

Continuing to debug the program, just three instructions later it returns to what looks like our next decoding routine.

[![Hancitor\_unicorn\_14](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_14-500x384.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_14.png)

*Figure 13 Decoding function*

Letting these blocks complete a few times validates we're in the right spot, as we quickly identify the MZ executable header.

[![Hancitor\_unicorn\_15](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_15-500x59.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_15.png)

*Figure 14 Validation of decoding*

We've now found the location of the encoded binary, due to RtlMoveMemory(), and the location of our function that we need to emulate.

### Function Copying

Analyzing this function, it's much less complex than the last one, but takes a different approach of iterating over a 12-byte key, located at 0x40743C in our example, and using it to XOR the encoded payload.

[![Hancitor\_unicorn\_16](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_16-500x89.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_16.png)

*Figure 15 12-byte XOR key*

We'll follow the same methodology as previous to add it into our program.

Starting at loc\_406442, we'll copy all of the bytes for the three blocks in the picture below, which is the decoding loop.

[![Hancitor\_unicorn\_17](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_17-500x324.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_17.png)

*Figure 16 Decoding loop and associated bytes*

Next we'll copy the XOR key and encoded payload into our script and build a test file so that it follows the following order of operation:

shellcode -\> key -\> payload

# loc\_406442 sc = b'\\x85\\xC9\\x7C\\x29\\x8B\\x35\\x40\\x90\\x40\\x00\\xB8\\x67\\x66\\x66\\x66\\xF 7\\xE9\\xC1\\xFA\\x02\\x8B\\xC2\\xC1\\xE8\\x1F\\x03\\xC2\\x8D\\x04\\x80\\x03\\xC0 \\x8B\\xD1\\x2B\\xD0\\x8A\\x82\\x3C\\x74\\x40\\x00\\x30\\x04\\x0E\\x41\\x3B\\x0D\\ x4C\\x90\\x40\\x00\\x72\\xCA' \# XOR Key sc += b'\\x48\\x45\\x57\\x52\\x54\\x57\\x45\\x57\\x45\\x54\\x48\\x47' encoded\_binary = b'\\x05\\x1F\\xC7\\x52\\x57\\x57\\x45\\x57\[truncated\]'

|-------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 | # loc\_406442 sc = b'\\x85\\xC9\\x7C\\x29\\x8B\\x35\\x40\\x90\\x40\\x00\\xB8\\x67\\x66\\x66\\x66\\xF 7\\xE9\\xC1\\xFA\\x02\\x8B\\xC2\\xC1\\xE8\\x1F\\x03\\xC2\\x8D\\x04\\x80\\x03\\xC0 \\x8B\\xD1\\x2B\\xD0\\x8A\\x82\\x3C\\x74\\x40\\x00\\x30\\x04\\x0E\\x41\\x3B\\x0D\\ x4C\\x90\\x40\\x00\\x72\\xCA' # XOR Key sc += b'\\x48\\x45\\x57\\x52\\x54\\x57\\x45\\x57\\x45\\x54\\x48\\x47' encoded\_binary = b'\\x05\\x1F\\xC7\\x52\\x57\\x57\\x45\\x57\[truncated\]' |

Looking at the code in the disassembler, we can tell there are a few values we'll have to prep before we can make this code run in our emulated environment. Specifically, we'll need to edit two MOV instructions and a CMP instruction that reference locations that don't exist in our code.

Based on our dynamic analysis, we know that the lpBuffer is a pointer to the address of the encoded payload, so we can change this instruction to move the starting location, where our payload will reside, into the ESI register. The current instruction is referencing an address in the data segment that holds the address to the payload. We'll replace it with an immediate MOV instruction by changing 0x8B3540904000 to 0xBE42000190, where 0x100042 is the start of our buffer. Since we changed the opcode, the length of our new instruction was one byte short and I padded it with a 0x90 -- NOP to keep everything aligned.

[![Hancitor\_unicorn\_18](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_18-500x100.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_18.png)

*Figure 17 Change location of payload*

The first MOV is for our encoded payload, the second MOV is for our XOR key. The second MOV uses a different opcode that plays more favorably to our needs, so we'll simply change the existing address to the location of the key by modifying 0x8A823C744000 to a value of 0x8A8236000001.

[![Hancitor\_unicorn\_19](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_19-500x97.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_19.png)

*Figure 18 Change location of the XOR key*

The final item to change is the compare instruction. Based off dynamic analysis, we know it's looking for the value 0x5000, so we'll change the opcode to support an immediate operand and modify 0x3B0D4C904000 to a value of 0x81F900500000.

[![Hancitor\_unicorn\_20](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_20-500x97.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_20.png)

*Figure 19 Hard-set compare value*

### Emulation

To set up our environment for this sample, the only value we need to worry about is EDX, which needs to be a pointer to our encoded payload, and gets moved into the EAX register during the loop. Similar to before, we'll setup our address space, define the architecture, map memory, and configure some initial register values.  
ADDRESS = 0x1000000 mu = Uc(UC\_ARCH\_X86, UC\_MODE\_32) mu.mem\_map(ADDRESS, 4 \* 1024 \* 1024) # Write code to memory mu.mem\_write(ADDRESS, X86\_CODE32) # Start of encoded data mu.reg\_write(UC\_X86\_REG\_EDX, 0x1000042) # Initialize ECX counter to 0 mu.reg\_write(UC\_X86\_REG\_ECX, 0x0) # Initialize Stack for functions mu.reg\_write(UC\_X86\_REG\_ESP, 0x1300000) print "Encrypt: %s" % mu.mem\_read(0x1000042,250) mu.emu\_start(ADDRESS, ADDRESS + len(X86\_CODE32)) print "Decrypt: %s" % mu.mem\_read(0x1000042,250)

|----------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | ADDRESS = 0x1000000 mu = Uc(UC\_ARCH\_X86, UC\_MODE\_32) mu.mem\_map(ADDRESS, 4 \* 1024 \* 1024) # Write code to memory mu.mem\_write(ADDRESS, X86\_CODE32) # Start of encoded data mu.reg\_write(UC\_X86\_REG\_EDX, 0x1000042) # Initialize ECX counter to 0 mu.reg\_write(UC\_X86\_REG\_ECX, 0x0) # Initialize Stack for functions mu.reg\_write(UC\_X86\_REG\_ESP, 0x1300000) print "Encrypt: %s" % mu.mem\_read(0x1000042,250) mu.emu\_start(ADDRESS, ADDRESS + len(X86\_CODE32)) print "Decrypt: %s" % mu.mem\_read(0x1000042,250) |

This yields the following result:

[![Hancitor\_unicorn\_21](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_21-500x84.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Hancitor_unicorn_21.png)

*Figure 20 Decrypted payload after running Python script*

If we take a look at this binary and peer at the strings, we can see that we're finally at the end of the road.

[![fig 21](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/fig-21-500x34.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/fig-21.png)

*Figure 21 Hancitor C2 URLs, external IP check, and Google remote check*

![great success-22](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/great-success-22-500x576.png)

To recap the process:

* Started with a Microsoft Word document
* Extracted base64 encoded shellcode
* Extracted encoded payload
* Emulated decoding function from shellcode to decode payload (binary)
* Extracted XOR key from new binary
* Extracted next encoded payload from new binary
* Emulated decoding function from new binary to decode Hancitor (binary)

Our last step is to put everything together into a nice package that we can use to scan thousands of Microsoft Word documents containing Hancitor and identify all of the C2 communications. Here's a link to the [Hancitor decoder script](https://github.com/pan-unit42/public_tools/blob/master/hancitor/hancitor_decrypt.py) we created.

For the purpose of this test, I took a small sample set of 10,000 unique Microsoft Word documents that were first seen on August 15, 2016 and observed by Palo Alto Networks WildFire as creating a process with a name of "WinHost32.exe". This, coupled with a few other criteria, gives me a corpus of testing samples that we know will be Hancitor and that I can run this script against.  
\[+\] FILE: fe23150ffec79eb11a0fed5e3726ca6738653c4f3b0f24dd9306f6460131b34c #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x13 \[-\] SIZE: 80556 \[!\] Success! Written to disk as fe23150ffec79eb11a0fed5e3726ca6738653c4f3b0f24dd9306f6460131b34c\_S1.exe #### PHASE 2 #### \[-\] XOR: HEWRTWEWETHG \[!\] Success! Written to disk as fe23150ffec79eb11a0fed5e3726ca6738653c4f3b0f24dd9306f6460131b34c\_S2.exe ### PHASE 3 ### \[-\] http://api.ipify.org \[-\] http://google.com \[-\] http://bettitotuld.com/ls3/gate.php \[-\] http://tefaverrol.ru/ls3/gate.php \[-\] http://eventtorshendint.ru/ls3/gate.php \[+\] FILE: fe7d4a583c1ae380eff25a11bda4f6d53b92d49a7a4d72c775b21488453bbc96 #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x13 \[-\] SIZE: 80556 \[!\] Success! Written to disk as fe7d4a583c1ae380eff25a11bda4f6d53b92d49a7a4d72c775b21488453bbc96\_S1.exe #### PHASE 2 #### \[-\] XOR: HEWRTWEWETHG \[!\] Success! Written to disk as fe7d4a583c1ae380eff25a11bda4f6d53b92d49a7a4d72c775b21488453bbc96\_S2.exe ### PHASE 3 ### \[-\] http://api.ipify.org \[-\] http://google.com \[-\] http://bettitotuld.com/ls3/gate.php \[-\] http://tefaverrol.ru/ls3/gate.php \[-\] http://eventtorshendint.ru/ls3/gate.php \[+\] FILE: fea98cc92b142d8ec98be6134967eacf3f24d5e089b920d9abf37f372f85530d #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x14 \[-\] SIZE: 162992 \[!\] Success! Written to disk as fea98cc92b142d8ec98be6134967eacf3f24d5e089b920d9abf37f372f85530d\_S1.exe #### PHASE 2 #### \[-\] XOR: ð~ð~ð~ \[!\] Detected Nullsoft Installer! Shutting down. \[+\] FILE: feb58e18dd320229d41d5b5932c14d7f2a26465e3d1eec9f77de211dc629f973 #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x13 \[-\] SIZE: 80556 \[!\] Success! Written to disk as feb58e18dd320229d41d5b5932c14d7f2a26465e3d1eec9f77de211dc629f973\_S1.exe #### PHASE 2 #### \[-\] XOR: HEWRTWEWETHG \[!\] Success! Written to disk as feb58e18dd320229d41d5b5932c14d7f2a26465e3d1eec9f77de211dc629f973\_S2.exe ### PHASE 3 ### \[-\] http://api.ipify.org \[-\] http://google.com \[-\] http://bettitotuld.com/ls3/gate.php \[-\] http://tefaverrol.ru/ls3/gate.php \[-\] http://eventtorshendint.ru/ls3/gate.php

|----------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 | \[+\] FILE: fe23150ffec79eb11a0fed5e3726ca6738653c4f3b0f24dd9306f6460131b34c #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x13 \[-\] SIZE: 80556 \[!\] Success! Written to disk as fe23150ffec79eb11a0fed5e3726ca6738653c4f3b0f24dd9306f6460131b34c\_S1.exe #### PHASE 2 #### \[-\] XOR: HEWRTWEWETHG \[!\] Success! Written to disk as fe23150ffec79eb11a0fed5e3726ca6738653c4f3b0f24dd9306f6460131b34c\_S2.exe ### PHASE 3 ### \[-\] http://api.ipify.org \[-\] http://google.com \[-\] http://bettitotuld.com/ls3/gate.php \[-\] http://tefaverrol.ru/ls3/gate.php \[-\] http://eventtorshendint.ru/ls3/gate.php \[+\] FILE: fe7d4a583c1ae380eff25a11bda4f6d53b92d49a7a4d72c775b21488453bbc96 #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x13 \[-\] SIZE: 80556 \[!\] Success! Written to disk as fe7d4a583c1ae380eff25a11bda4f6d53b92d49a7a4d72c775b21488453bbc96\_S1.exe #### PHASE 2 #### \[-\] XOR: HEWRTWEWETHG \[!\] Success! Written to disk as fe7d4a583c1ae380eff25a11bda4f6d53b92d49a7a4d72c775b21488453bbc96\_S2.exe ### PHASE 3 ### \[-\] http://api.ipify.org \[-\] http://google.com \[-\] http://bettitotuld.com/ls3/gate.php \[-\] http://tefaverrol.ru/ls3/gate.php \[-\] http://eventtorshendint.ru/ls3/gate.php \[+\] FILE: fea98cc92b142d8ec98be6134967eacf3f24d5e089b920d9abf37f372f85530d #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x14 \[-\] SIZE: 162992 \[!\] Success! Written to disk as fea98cc92b142d8ec98be6134967eacf3f24d5e089b920d9abf37f372f85530d\_S1.exe #### PHASE 2 #### \[-\] XOR: ð~ð~ð~ \[!\] Detected Nullsoft Installer! Shutting down. \[+\] FILE: feb58e18dd320229d41d5b5932c14d7f2a26465e3d1eec9f77de211dc629f973 #### PHASE 1 #### \[-\] ADD: 0x3 \[-\] XOR: 0x13 \[-\] SIZE: 80556 \[!\] Success! Written to disk as feb58e18dd320229d41d5b5932c14d7f2a26465e3d1eec9f77de211dc629f973\_S1.exe #### PHASE 2 #### \[-\] XOR: HEWRTWEWETHG \[!\] Success! Written to disk as feb58e18dd320229d41d5b5932c14d7f2a26465e3d1eec9f77de211dc629f973\_S2.exe ### PHASE 3 ### \[-\] http://api.ipify.org \[-\] http://google.com \[-\] http://bettitotuld.com/ls3/gate.php \[-\] http://tefaverrol.ru/ls3/gate.php \[-\] http://eventtorshendint.ru/ls3/gate.php |

### Analysis

The results were fairly unimpressive, however you win some and you lose some. It still provides some interesting observations.

For our sample set, there were only 3 C2 URLs across all 8,851 Hancitor payloads we successfully decoded:  
hxxp://bettitotuld\[.\]com/ls3/gate.php hxxp://tefaverrol\[.\]ru/ls3/gate.php hxxp://eventtorshendint\[.\]ru/ls3/gate.php

|-------|---------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | hxxp://bettitotuld\[.\]com/ls3/gate.php hxxp://tefaverrol\[.\]ru/ls3/gate.php hxxp://eventtorshendint\[.\]ru/ls3/gate.php |

Looking at the stage 1 payloads, we decoded 9,967, which is almost the entire set. Reviewing the metadata for the PE files, 8,851 exhibited the following characteristics, which are included in a YARA rule at the end of this document.

CompanyName: 'SynapticosSoft, Corporation.'  
OriginalFilename: 'MpklYuere.exe'  
ProductName: 'ngqlgdA'

Additionally, we identified three XOR keys being used in stage 1:  
13 \[-\] XOR: 0xe 1103 \[-\] XOR: 0x14 8851 \[-\] XOR: 0x13

|-------|-------------------------------------------------------------|
| 1 2 3 | 13 \[-\] XOR: 0xe 1103 \[-\] XOR: 0x14 8851 \[-\] XOR: 0x13 |

After correlating the data, each of the keys corresponded to a different stage 2 dropper and our script was designed to target and decoded the most heavily used. General observations for the other two decoders are that the one with key 0xE uses the same XOR key for the second stage Hancitor payload "HEWRTWEWETHG" and would likely be straightforward to add to the decoding script. The 1,103 other files with key 0x14 were identified as Nullsoft Installers.

For the 8,851 that successfully decoded their stage 2 payload, I did not note any PE's with any file information; however, a YARA rule is included which matches them all. The last thing I'll mention regarding the stage 2 files is the different file sizes.  
3 \[-\] SIZE: 114688 10 \[-\] SIZE: 109912 1103 \[-\] SIZE: 162992 8851 \[-\] SIZE: 80556

|---------|-------------------------------------------------------------------------------------------|
| 1 2 3 4 | 3 \[-\] SIZE: 114688 10 \[-\] SIZE: 109912 1103 \[-\] SIZE: 162992 8851 \[-\] SIZE: 80556 |

This data is pulled from the variable in our shellcode and we can see that there is a slight file size variation in the 13 that used the XOR key 0xE, which might imply slightly modified payloads.

### Conclusion

Hopefully this was an educational demonstration using the extremely powerful Unicorn Engine to build a practical malware decoder. These techniques can be applied to many different samples of malware and can free you up from the more tedious process of figuring out how to program a slew of bitwise interactions and focus more on analysis and countermeasures.

### Indicators

At the following [GitHub repository](https://github.com/pan-unit42/public_tools/tree/master/hancitor), you will find 3 YARA rules, listed below, which can be used to detect the various pieces described throughout these two blogs, and the script that was built throughout this blog for decoding Hancitor.

hancitor\_dropper.yara -- Detect Microsoft Word document dropper  
hancitor\_stage1.yara -- Detect first PE dropper  
hancitor\_payload.yara -- Detect Hancitor malware payload
Back to top

### Tags

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [Scam](https://unit42.paloaltonetworks.com/tag/scam/ "scam")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Exploring the Cybercrime Underground: Part 2 -- The Forum Ecosystem](https://unit42.paloaltonetworks.com/unit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem/ "Exploring the Cybercrime Underground: Part 2 – The Forum Ecosystem")

### Related Articles

* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")
* [When "Hi, This Is IT" Comes Through Microsoft Teams](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
