RARSTONE is a custom Windows backdoor associated with the Naikon espionage group. It has been used in targeted intrusions against government, diplomatic, military, intelligence, aviation, and other state-linked organizations in the Asia-Pacific region, particularly around the South China Sea. Documented Naikon operations used spear-phishing lures exploiting CVE-2012-0158 to deploy the malware.
RARSTONE supports encrypted command-and-control communications using SSL. After decrypting itself in memory, it can retrieve an additional DLL payload from its command-and-control infrastructure and load that module into the memory space of a hidden Internet Explorer process, indicating in-memory execution and process injection tradecraft intended to reduce visibility and blend malicious traffic with legitimate browser activity. These behaviors are consistent with a modular backdoor used for post-compromise control and stealthy payload execution.
RARSTONE is best characterized as an espionage backdoor used by Naikon in long-running targeted campaigns against regional government and strategic-sector entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Naikon group used mostly spear-phished documents for the attacks, with CVE-2012-0158 exploits that dropped the group’s signature backdoor. | Naikon is known for its custom backdoor, called RARSTONE.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The backdoor connects to the command server located at philippinenews[.]mooo[.]com.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that downloads a DLL from C2 and loads it into the memory of a hidden Internet Explorer process without dropping it to disk.
Custom backdoor associated with the Naikon group; in this report it is described as the signature malware dropped via spear-phishing documents exploiting CVE-2012-0158.
Decrypts in memory, downloads a DLL from C2, and loads it into a hidden Internet Explorer process without dropping it to disk.
Malware that uses SSL to encrypt communications with its C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.