BLOODALCHEMY is a Windows x86 backdoor written in C and deployed as injected shellcode through a dedicated loader. It is an evolution of DeedRAT within the ShadowPad lineage. The implant has been associated with the China-nexus REF5961 espionage intrusion set targeting an ASEAN foreign affairs ministry and has also been used in the SilkParasite campaign against Central Asian government organizations. BLOODALCHEMY has been loaded through DLL sideloading of a trusted application and executed within a benign process. It supports host reconnaissance, configurable persistence through services, Registry Run entries, scheduled tasks, and Task Scheduler COM, as well as process injection using APC-based techniques. It communicates through HTTP, named pipes, and socket-based channels, with support for proxy use, encryption, compression, and Base64 encoding. Operators can update implant components, execute payloads, collect system and network information, and remove the implant and its persistence artifacts. Reported SilkParasite variants also included plugins for clipboard logging, keystroke capture, and execution under another user session.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Part of this intrusion set includes a new x86-based backdoor called BLOODALCHEMY.
BloodAlchemy IOCs include a C2 URL, an encryption key, fl_bridge scheduled-task persistence, malicious DLL/binary samples, and decrypted shellcode.
...phishing emails to deliver a variant of BLOODALCHEMY and custom backdoors such as kidsRAT and RustVoralix.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
As a scheduled task, running with SYSTEM privilege via schtasks.exe: schtasks.exe /CREATE ... /RU "NT AUTHORITY\\SYSTEM".
Its operators used spear-phishing emails with password-protected RAR archives, then used document macros to trigger malicious code.
As a scheduled task, running with SYSTEM privilege via schtasks.exe: schtasks.exe /CREATE ... /RU "NT AUTHORITY\\SYSTEM".
0x1302 load received payload and store it into registry value 0x1303 delete registry value
As a scheduled task, running with SYSTEM privilege via schtasks.exe: schtasks.exe /CREATE ... /RU "NT AUTHORITY\\SYSTEM".
BloodAlchemy included capabilities for clipboard logging, keystroke capture, and running processes under another user’s session.
[It can] create a Windows process from a hardcoded list and inject a shellcode... using the WriteProcessMemory+QueueUserAPC+ResumeThread method.
impapi (user-session impersonation and process execution under another user’s context)
To hide its strings the BLOODALCHEMY malware uses a classic technique where each string is encrypted, preceded by a single-byte decryption key...
“A TLS certificate issued by a Chinese state-affiliated certificate authority associated with the infrastructure impersonates Uzbekistan's state railway authority.”
BloodAlchemy included capabilities for clipboard logging, keystroke capture, and running processes under another user’s session.
[It can] create a Windows process from a hardcoded list and inject a shellcode... using the WriteProcessMemory+QueueUserAPC+ResumeThread method.
The malware supports basic commands to gather host information, overwrite the malware binary, the loader, or the main trusted binary that's vulnerable to DLL sideloading, and terminate and uninstall itself.
impapi (user-session impersonation and process execution under another user’s context)
この悪性 DLL は同じフォルダ内の DIFX を読み込み、読み込んだデータから Shellcode を復号し、メモリ内でこの Shellcode を実行します。Shellcode の復号に使われているアルゴリズムは AES128(CBC モード)
Payload にはサンドボックスへの耐解析機能(Anti Sandbox)も含まれています。... process_name やファイル、DNS の結果を確認します。
BLOODALCHEMY will try to use any proxy server found in the registry key SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings.
While waiting for a client to connect to this named pipe the malware scans the running processes and checks that its parent process is still running.
One host information gathering command: CPU, OS, display, network, etc.
Rather than using one noisy implant, the actors maintained several tools, changed their supporting files between builds, and used cloud services and normal-looking traffic to make investigation harder.
When using the HTTP protocol the malware requests the following URI /Inform/logger/.
From the malware strings and imports we know that the malware can also operate using TCP/UDP sockets... DNS:// ... UDP:// ... SMB:// ... TCP://.
It runs its command channel over trusted services like Google Drive, hides inside legitimately signed applications, and keeps its footprint deliberately small.
Nearly every family in SilkParasite is built around plugin architecture: the implant loads additional capabilities on demand from its command-and-control server rather than shipping them all at once.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an infrastructure association for a railway-themed domain; the content provides no behavioral or campaign details.
Malware or tooling family associated in the report with a railway-themed domain within the broader infrastructure investigation.
A named malware family whose reported C2 domain shares Uzbekistan railway-themed impersonation with the infrastructure cluster. No behavior, delivery, or initial-access details are provided.
A previously known remote-access trojan family included in the SilkParasite cyberespionage toolset targeting Central Asian government bodies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.