VELETRIX is a malware loader associated in the provided content with the DragonClone campaign and likely linked to deployment of VShell. It was observed targeting China Mobile Tietong Co., Ltd., a subsidiary of China Mobile, via spearphishing emails carrying a malicious ZIP archive themed as an internal employee training program. The archive contained legitimate binaries and malicious DLL files and abused DLL side-loading through a Wondershare Recoverit-themed executable and a malicious drstat.dll dependency. The sideloaded DLL was described as a customized VELETRIX loader, with its main malicious logic in the exported function dr_data_stop.
The loader uses anti-sandbox checks involving GetTickCount, Sleep, and Beep; dynamic API resolution via LoadLibraryA and GetProcAddress; and shellcode obfuscation using IPv4 address strings converted back to bytes with RtlIpv4StringToAddressA. The shellcode is decrypted with XOR key 0x6f and executed in memory by passing it as a callback to EnumCalendarInfoA. The shellcode then resolves APIs by traversing the PEB and using a ROR13-based hashing algorithm. It initializes Winsock networking and communicates over TCP with hardcoded command-and-control infrastructure, including 62.234.24.38:9999. According to the content, it sends a beacon containing the second-loader version string "w64" and the C2 IP address, receives nearly 5 MB of XOR-encrypted second-stage data, decrypts it with XOR key 0x99, and executes the payload in memory.
The second stage was identified in the content as a packed Golang DLL consistent with reverse-shell capability and publicly linked intelligence suggests VELETRIX is used to load VShell directly in memory. Additional related samples cited in the content used alternate C2 addresses 121.37.80.227 and 156.238.236.130. Reported hashes and artifacts include the phishing ZIP archive SHA256 fef69f8747c368979a9e4c62f4648ea233314b5f41981d9c01c1cdd96fb07365, a decrypted second-stage DLL SHA256 c9dc947b793d13c3b66c34de9e3a791d96e34639c5de1e968fb95ea46bd52c23, a related shellcode sample SHA256 a15f30f20e3df05032445697c906c3a2accf576ecef5da7fad3730ca5f9c141c, and a related loader sample SHA256 27c04c7d2d6dbbb80247adae62e76dfa43c39c447f51205e276b064555a6eb84.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The component that was Sideloaded is a DLL that Wondershare contains a dependency on, which the Threat Actor replaced with a loader customized by the adversary identified as VELETRIX.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
After extracting the Shellcode from the binary’s Resource, the Loader will implement three routines: Loading of Undocumented APIs required for injection into the Thread; Allocation of Memory with Execution permissions to allocate the Shellcode; Execution of the Shellcode through a Thread. | VELETRIX’s main function is to start the dynamic API loading routine with LoadLibraryA and GetProcAddress... The first action to be performed is to collect the kernel32.dll DLL by accessing the memory structures through the PEB.
the adversary tries to evade detection and hinder the analysis through the Stack Strings technique... These addresses together are the encrypted shellcode that VELETRIX loads upon execution. | the one with Hash 27c04c7d2d6dbbb80247adae62e76dfa43c39c447f51205e276b064555a6eb84, we can see that it is actually a Loader that loads and executes the decrypted Shellcode in memory. This Loader loads the decrypted Shellcode into the only Resource present in the binary, identified by ID 101.
VELETRIX implements an unconventional method of Shellcode injection, opting to use the EnumCalendarInfoA API... the API will execute the code present in the address given in the first argument lpCalInfoEnumProc.
the first routine to be executed is the Anti-Sandbox routine, executing the GetTickCount in the beginning and in the end of the Anti-Sandbox loop. The loop is compound by a 10 seconds sleep (with Sleep API) and checking the sound in the system with Beep call.
the first routine to be executed is the Anti-Sandbox routine, executing the GetTickCount in the beginning and in the end of the Anti-Sandbox loop. The loop is compound by a 10 seconds sleep (with Sleep API) and checking the sound in the system with Beep call.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VELETRIX is a loader malware that uses DLL side-loading to execute shellcode and load additional frameworks such as VShell directly in memory, facilitating post-exploitation activities.
VELETRIX is a malicious DLL sideloaded via a legitimate Wondershare executable. It performs anti-sandbox checks, dynamically resolves APIs, decodes shellcode hidden as IPv4 strings, decrypts it with XOR 0x6f, and executes it via EnumCalendarInfoA. The shellcode then connects to a C2 server, receives an encrypted second stage, decrypts it with XOR 0x99, and executes it in memory.
Malware loader used in targeted attacks, employing anti-sandbox and obfuscation techniques to deploy additional payloads such as VShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.