Deuterbear
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"In 2022, Earth Hundun began using the latest version of Waterbear — also known as Deuterbear — ... we consider it a different malware entity from the original Waterbear."
"In 2022, Earth Hundun began using the latest version of Waterbear — also known as Deuterbear — ... we consider it a different malware entity from the original Waterbear."
Techniques & procedures
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
2 techniquesPersistence
1 techniquePrivilege Escalation
1 techniqueStealth
4 techniques“uses the same custom salted RC4 decryption… to decrypt the downloader… [and] uses the CryptUnprotectData API.”
“Targets specific path/registry in the victim’s environment” and “Note that the CLSID value is unique and defined during malware installation.”
Discovery
4 techniques“Query password from registry… Query path of encrypted downloader from registry… [then] Downloader decryption…”
“Downloaders check for internet connectivity on compromised systems.”
Command and Control
3 techniques“Downloaders communicate with C&C by HTTP/HTTPS” and “Deuterbear downloader enables HTTPS tunnel”
“Encodes traffic with a non-standard RC4 to make the content of traffic more difficult to detect”
“Employs a RC4/RSA to conceal command and control traffic” and “The downloader… generate an RSA… [then] RC4_KEY_1 and RC4_KEY_2… encrypted by RSA”
Exfiltration
1 techniqueRecent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.