BellaCPP is a C++ reimplementation of the BellaCiao malware family, discovered on the same infected machine in Asia as an older .NET BellaCiao sample. BellaCiao is described as a webshell-tunneling hybrid first identified in 2023, and BellaCPP closely mirrors that functionality. The malware is a PE32+ x86-64 Windows DLL named adhapl.dll, located in C:\Windows\System32, and exports a single function, ServiceMain, indicating it is intended to run as a Windows service. BellaCPP decrypts strings with XOR key 0x7B, including the path C:\Windows\System32\D3D12_1core.dll and the function names SecurityUpdate and CheckDNSRecords. It loads the secondary DLL D3D12_1core.dll and resolves those functions via GetProcAddress. BellaCPP generates domains in the format <5 random letters><target identifier>.<country code>.systemupdate[.]info, invokes CheckDNSRecords, and only calls SecurityUpdate if the DNS response matches a hardcoded IP address. The parameter passed to SecurityUpdate is formatted as <username>:<password>:systemupdate[.]info:<port>:<IP_address>:<port>:<IP_address>:<port>. Researchers were unable to recover the secondary DLL, but assessed with medium confidence that it creates an SSH tunnel based on the parameter structure and similarities to known BellaCiao behavior. Unlike older BellaCiao samples, BellaCPP does not contain the hardcoded PowerShell webshell. It has been associated with Charming Kitten/APT35 with medium-to-high confidence because it mirrors BellaCiao logic, uses previously attributed domains, and was found alongside an older BellaCiao sample. Known sample identifiers for BellaCPP include MD5 222380fa5a0c1087559abbb6d1a5f889, SHA1 dccdfc77dd2803b3c5a97af0851efa0aa5bbeeeb, and SHA256 e4e3f09c4257269cef6cfbebc83c8a60376ce5e547080502e3e408a3f9916218.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After further investigation of the sample, it turned out to be a reimplementation of an older BellaCiao version, but written in C++.
The period opened with the discovery of BellaCPP, a C++ reimplementation of the group's established BellaCiao .NET implant — a webshell-tunneling hybrid first identified in 2023...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent years, Iranian-linked threat actors have commonly used phishing (T1566) as the primary vector for initial access, often leading to execution via user execution (T1204) of malicious files
Decrypt three strings using XOR encryption with the key 0x7B : C:\Windows\System32\D3D12_1core.dll SecurityUpdate CheckDNSRecords Load the DLL file at the path decrypted during the previous step and resolve the functions of the two other decrypted strings above with GetProcAddress.
High-level obfuscation and custom code: Designed to bypass security tools that rely on identifying known malware signatures or behaviors.
Load the DLL file at the path decrypted during the previous step and resolve the functions of the two other decrypted strings above with GetProcAddress.
Decrypt three strings using XOR encryption with the key 0x7B : C:\Windows\System32\D3D12_1core.dll SecurityUpdate CheckDNSRecords Load the DLL file at the path decrypted during the previous step and resolve the functions of the two other decrypted strings above with GetProcAddress.
Generate a domain using the pattern below and send a DNS request to obtain the IP address.
BellaCiao (and BellaCPP) is a personalized dropper capable of delivering other malware payloads based on C2 commands.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ reimplementation of BellaCiao, described as a webshell-tunneling hybrid used by APT35.
C++ variant of BellaCiao malware observed in the wild.
A C++ DLL variant/reimplementation of BellaCiao designed to run as a Windows service. It decrypts strings, loads another DLL, generates actor-style domains, performs DNS-based checks, and likely triggers creation of an SSH tunnel via a secondary DLL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.