Darktrace published a technical walkthrough of unpacking and analyzing SnappyBee (aka Deed RAT), a modular backdoor previously reported in China-linked espionage activity attributed to Salt Typhoon (aka Earth Estries). The write-up describes SnappyBee as typically deployed post-compromise to establish persistence and enable follow-on tooling (including Cobalt Strike and the Demodex rootkit), and highlights its use of a custom packing routine intended to obscure the payload and hinder static analysis.
Zscaler ThreatLabz detailed GuLoader’s evolving obfuscation methods designed to evade detection and frustrate reverse engineering. Techniques described include polymorphic “dynamic constant construction” (building constants at runtime via instruction sequences like mov, xor, add, sub) and exception-based control-flow redirection that replaces normal jmp logic with deliberately triggered CPU exceptions handled by custom exception handlers (e.g., 0x80000003 STATUS_BREAKPOINT, 0x80000004 STATUS_SINGLE_STEP, 0xC0000005 STATUS_ACCESS_VIOLATION), complicating automated tracing and signature-based detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Darktrace released an educational analysis of the SnappyBee (Deed RAT) modular backdoor, describing its DLL side-loading chain, ARC4-based in-memory decryption, nested unpacking, and debugging-based extraction method, along with sample SHA-256 indicators.
Zscaler ThreatLabz published a technical analysis of GuLoader’s evolving obfuscation and evasion methods and released IDA scripts to help analysts recover constants and strings and remove exception-based control-flow obfuscation.
In versions observed after 2022, GuLoader updated its dynamic hashing by combining DJB2 with extra XOR operations and a hardcoded DWORD to resolve APIs and identifiers while limiting static indicators.
Across 2024 into 2025, GuLoader broadened its exception-based control-flow obfuscation to support additional exception types and more complex jump-target calculations, including hardcoded offsets and dynamically generated XOR keys.
In 2023, GuLoader evolved its string protection by constructing and decrypting strings on the stack at runtime, reducing the effectiveness of static signatures and making emulation more useful for recovery.
By 2022, GuLoader samples used statically stored XOR-encrypted strings, dynamic constant construction, API hashing, and exception-based control-flow obfuscation to hinder static analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.