Enfal, also referred to as Lurid in overlapping reporting, is a Windows malware family associated with long-running Chinese cyber-espionage activity. It has been linked to multiple China-aligned intrusion sets, including clusters tracked as PittyTiger, APT15, APT27, BRONZE UNION, and other operators that appear to share tooling or infrastructure. Enfal has been observed in campaigns targeting government entities and other strategic organizations in Asia, including Mongolian government targets, and has also appeared in broader espionage ecosystems using shared delivery and staging components.
Enfal is closely associated with the Cmstar downloader/loader lineage. In documented operations, attackers used spearphishing emails carrying weaponized Microsoft Office documents that exploited vulnerabilities such as CVE-2012-0158, and in some later cases also CVE-2014-1761, to install Cmstar and related components that led to Enfal-linked activity. Reporting also connects Enfal-like payload delivery to Royal Road-generated RTF lure documents exploiting Equation Editor flaws in later campaigns.
The malware ecosystem emphasizes covert command-and-control and staged delivery. Related Enfal/Lurid tooling has been documented using XOR-based encryption for outbound communications and compressing data before transmission. Associated components profile infected hosts, communicate over HTTP-based C2 channels, and establish persistence through autorun mechanisms. Enfal-linked tradecraft also includes defense-evasion measures such as string and configuration obfuscation, manual API resolution in associated loaders, and process checks intended to identify security software or analysis environments.
A notable feature of the broader Enfal ecosystem is use of steganography in at least some associated loaders. Zero.T, a loader tied to the Enfal ecosystem, was observed retrieving apparently benign bitmap images containing hidden malicious modules embedded in pixel data, then extracting those modules after persistence was established. This reflects a multi-stage architecture designed to conceal payload delivery and hinder network inspection.
Enfal is best characterized as an espionage-oriented backdoor or remote access trojan used within a modular intrusion set rather than as a standalone commodity malware family. Its observed behavior and operational context indicate use for persistent access, host reconnaissance, payload retrieval, and data theft in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed an attack on the Royal Road by Vicious Panda in March 2020. It has been reported to execute malware similar to Enfal and BYEBY.
Tools: Sysupdate, China Chopper, OwaAuth, ZxShell, Gh0st RAT, PoisonIvy, Hunter, PlugX, Enfal, HttpBrowser, 9002, ASPXSpy, HyperBro
6 distinct techniques documented for this family, organized by ATT&CK tactic.
"AppleSeed has compressed collected data before exfiltration."; "APT28 used a publicly available tool to gather and compress multiple documents..."; "Aria-body has used ZIP to compress data..."; "Cadelspy...compress stolen data into a .cab file."; "Daserf hides collected data in password-protected .rar archives."; "FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration."; "Lazarus Group has compressed exfiltrated data with RAR...archive specified directories in .zip format"; "XCSSET will compress entire ~/Desktop folders..."
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
Cmstar also decrypts a 752-byte piece of shellcode that carries out communications with the C2 server, specifically by sending HTTP POST requests to the following URL
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Экосистема вредоносных модулей, чьи компоненты доставлялись через BMP-контейнеры со стеганографией.
Malware family referenced as used by multiple Chinese threat actors and linked via historical infrastructure/registrant patterns.
Backdoor that uses XOR encryption.
A malware family referenced as similar to payloads executed by Vicious Panda in Royal Road-related attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.