Rietspoof is a low-prevalence, rapidly evolving multi-stage Windows malware family first observed in 2018. It operates as a staged infection chain that has included a malicious macro-enabled Microsoft Word document, an obfuscated Visual Basic Script component, an intermediate archive stage, a signed executable bot or downloader, and a later fileless payload-execution stage. The malware was under active development during the period it was tracked, with frequent redesigns of both its staging logic and command-and-control protocol.
Initial access has been associated with social-engineering lures delivered through email and instant-messaging channels, including malicious Word documents that prompt victims to enable macros. After execution, early-stage script components deobfuscate and launch subsequent payloads, extract embedded content, invoke native Windows utilities to continue the chain, and remove intermediate artifacts. Rietspoof also employed anti-analysis and defense-evasion measures, including temporary system date manipulation, heavy script obfuscation, valid digital signatures on some stages, and self-deletion behavior.
Rietspoof establishes persistence through multiple mechanisms observed across variants, including scheduled-task creation, startup-folder shortcut placement, and optional installation of a later-stage component as a Windows service. Mid-chain executable stages function as bot or downloader components capable of receiving commands to download additional files, upload data, execute processes, delete files, and self-destruct. Later stages were designed to retrieve and execute follow-on payloads, including fileless execution through a command shell with redirected input and output over an authenticated channel.
Its command-and-control implementation changed substantially over time. Observed variants used encrypted communications over raw TCP and later added HTTP and HTTPS-capable traffic, with custom key-derivation approaches and indications of geofenced tasking based on victim location. The malware’s ultimate objectives, victimology, and final payloads were not conclusively established, but its architecture and behavior are consistent with a modular downloader or loader used to deliver additional malicious capability onto compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
First, the script deletes a scheduled task, Microsoft Windows DOM object helper. This is done to ensure that a new task in the scheduler, pointing to the expanded PE file, will execute after exactly one minute.
This allows the downloader to execute the next payload filelessly.
An interesting move by the malware authors is to use cmd /c to run commands from the command line... most likely an attempt to break behavioural detections by recursively spawning new command line instances.
Once macros are enabled, the information regarding the protected document is deleted... Afterwards, this part of the script deobfuscates the VBS and saves it onto the machine | It delivers a highly obfuscated Visual Basic Script with a hard-coded and encrypted second stage — a CAB file.
First, the script deletes a scheduled task, Microsoft Windows DOM object helper. This is done to ensure that a new task in the scheduler, pointing to the expanded PE file, will execute after exactly one minute.
First, the script deletes a scheduled task, Microsoft Windows DOM object helper. This is done to ensure that a new task in the scheduler, pointing to the expanded PE file, will execute after exactly one minute.
Afterwards, a communication with the C&C server over the aforementioned channel is established and two pipes are created.
The first part of the Visual Basic script is a function for reading and deobfuscating embedded binaries.
The script creates a new LNK file in Startup with the name WindowsUpdate.lnk.
Afterwards, a communication with the C&C server over the aforementioned channel is established and two pipes are created.
Afterwards, as the CAB file has already been expanded, it is deleted from %TEMP%. The expanded executable file is run, and the original script is deleted to cover its tracks.
The script first checks if the logged user is an Admin by simply reading the registry key "HKEY_USERS\S-1-5-19\Environment\TEMP".
At the beginning, information about the infected device (HW and ID info) is retrieved by the script.
This stage has the capabilities of a simple bot: it can download/upload files, start processes, or initiate a self-destruct function.
The command HARDWARE induces the request “HW:<OS info> CPU<CPU info> RAM: <RAM info> USER: <process privileges>”
DEL:<filename> Delete file... UPL:<filename> Upload file from %TEMP%
In version two, the protocol not only supports its own protocol running over TCP, but it also tries to leverage HTTP/HTTPS requests.
The second version tries to communicate over HTTP/HTTPS unless a proxy is set up, in which case it resorts to raw TCP.
the third stage uses a simple TCP protocol to communicate with its C&C
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage malware family delivered via VBS/CAB/PE stages and later also via a macro-enabled Word document. It uses staged downloaders and bot functionality, supports file upload/download, process execution, self-destruct, persistence via scheduled task/LNK/service installation, geofenced C2 behavior, AES-CBC-encrypted communications over TCP and HTTP/HTTPS, and a Stage 4 downloader that authenticates to C2 over NTLM to retrieve additional payloads.
A multi-stage malware family delivered via VBS and later also via malicious Word macros. It drops and executes additional stages, uses signed executables, establishes persistence via scheduled tasks and startup LNK files, communicates with C2 using custom AES-CBC-encrypted protocols over TCP and HTTP/HTTPS, performs basic bot functions such as file upload/download, process execution, and self-destruct, and includes a later downloader stage that authenticates over NTLM to retrieve further payloads.
A multi-stage malware family delivered via malicious Word documents and VBS scripts. It uses CAB and PE stages, supports downloading additional payloads, remote-control commands, file upload/download, process execution, self-deletion, persistence via scheduled tasks and LNK startup entries, and later deploys a fileless payload through an NTLM-authenticated C2 channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.