WaterBear is a Windows malware family active since at least 2009 and described as having more than 10 versions. The provided content characterizes it as a multifaceted stage-two implant capable of file transfer, shell access, screen capture, and additional backdoor functionality. Observed behaviors include DLL side-loading to import and load a malicious DLL loader; deletion of specific Registry values to facilitate loading of a malicious DLL; querying the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\MTxOCI for the OracleOcilib value; checking for the presence of specific security software; injecting decrypted shellcode into the LanmanServer service; hooking ZwOpenProcess and GetExtendedTcpTable in security-product processes to hide PIDs and TCP records; scrambling functions with random values to prevent re-execution; and leveraging API functions for execution. The content also associates WaterBear with BlackTech reporting, including U.S. and Japanese government advisories that listed WaterBear among custom malware used to target multiple Cisco router versions. High-confidence associations in the content include reporting by Trend Micro and TeamT5 on the family and its long-running activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the agencies said they have observed multiple Cisco versions targeted with custom malware, including BendyBear, Bifrose, BTSDoor FakeDead (a.k.a. TSCookie), Flagpro, FrontShell (FakeDead’s downloader module) IconDown PLEAD, SpiderPig, SpiderSpring, SpiderStack and WaterBear.
"...including Waterbear, a malware entity that has had over 10 versions since 2009."
30 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
“bypass antivirus software adding a large amount of padding with 0x00 around the beginning and end to avoid detection.”
Transmits payloads in modified RC4-encrypted chunks... Table 1 ... Payloads in modified RC4-encrypted chunks ... T1027.002: Obfuscated Files or Information: Software Packing
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
“Makes the patched executable that appears legitimate or benign to users and/or security tools”
The content repeatedly describes malware and threat actors injecting shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, cmd.exe, lsass.exe, and browser processes.
Bisonal has deleted Registry keys to clean up its prior activity. FIN8 has deleted Registry keys during post compromise cleanup activities. SUNBURST also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
During execution, the code employs byte randomization... using the host’s current time as a seed... ~65 calls to Windows API kernel32!GetTickCount... T1497.003: Time Based Evasion
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
“Downloaders check for internet connectivity on compromised systems.”
“Waterbear RAT lists network connections… by querying for information over the network.”
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The shellcode begins by locating the target’s Process Environment Block (PEB) to check if it’s currently being debugged... This routine is performed 52 times... Table 1 ... T1082: System Information Discovery
“RAT searches files and directories or in specific locations.”
During execution, the code employs byte randomization... using the host’s current time as a seed... ~65 calls to Windows API kernel32!GetTickCount... T1497.003: Time Based Evasion
The BendyBear sample was determined to be x64 shellcode for a stage-zero implant whose sole function is to download a more robust implant from a command and control (C2) server... Table 1 ... Payload transfer from remote host ... T1105: Ingress Tool Transfer
“Encodes traffic with a non-standard RC4 to make the content of traffic more difficult to detect”
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A complex backdoor/RAT ecosystem used by Earth Hundun/BlackTech, featuring loader+downloader stages, custom (salted) RC4 and/or CryptUnprotectData-based decryption flows, extensive anti-analysis (anti-debug/anti-sandbox/AV evasion, binary padding, anti-memory scanning), and a custom C2 protocol to retrieve a next-stage RAT with broad remote administration and file/process/service/registry capabilities.
BlackTech-linked custom malware used to maintain covert access and persistence in targeted networks.
Backdoor malware that injects decrypted shellcode into the LanmanServer service.
This article is Part 2 of a series of articles. Click here to read Part 1: Waterbear Malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.