Darktrace published a technical walkthrough of unpacking and analyzing SnappyBee (aka Deed RAT), a modular backdoor previously reported in China-linked espionage activity attributed to Salt Typhoon (aka Earth Estries). The write-up describes SnappyBee as typically deployed post-compromise to establish persistence and enable follow-on tooling (including Cobalt Strike and the Demodex rootkit), and highlights its use of a custom packing routine intended to obscure the payload and hinder static analysis.
Zscaler ThreatLabz detailed GuLoader’s evolving obfuscation methods designed to evade detection and frustrate reverse engineering. Techniques described include polymorphic “dynamic constant construction” (building constants at runtime via instruction sequences like mov, xor, add, sub) and exception-based control-flow redirection that replaces normal jmp logic with deliberately triggered CPU exceptions handled by custom exception handlers (e.g., 0x80000003 STATUS_BREAKPOINT, 0x80000004 STATUS_SINGLE_STEP, 0xC0000005 STATUS_ACCESS_VIOLATION), complicating automated tracing and signature-based detection.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Darktrace released an educational analysis of the SnappyBee (Deed RAT) modular backdoor, describing its DLL side-loading chain, ARC4-based in-memory decryption, nested unpacking, and debugging-based extraction method, along with sample SHA-256 indicators.
Zscaler ThreatLabz published a technical analysis of GuLoader’s evolving obfuscation and evasion methods and released IDA scripts to help analysts recover constants and strings and remove exception-based control-flow obfuscation.
In versions observed after 2022, GuLoader updated its dynamic hashing by combining DJB2 with extra XOR operations and a hardcoded DWORD to resolve APIs and identifiers while limiting static indicators.
Across 2024 into 2025, GuLoader broadened its exception-based control-flow obfuscation to support additional exception types and more complex jump-target calculations, including hardcoded offsets and dynamically generated XOR keys.
In 2023, GuLoader evolved its string protection by constructing and decrypting strings on the stack at runtime, reducing the effectiveness of static signatures and making emulation more useful for recovery.
By 2022, GuLoader samples used statically stored XOR-encrypted strings, dynamic constant construction, API hashing, and exception-based control-flow obfuscation to hinder static analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.