Cybereason reported that ShadowWali is a newly analyzed variant in the xxmm backdoor family, a malware set linked to long-running intrusions against Japanese organizations and assessed as either an earlier form of Wali or a closely related sibling developed by the same author, identified as "123". The malware continues the family’s tradecraft of using unusually large binaries, process injection, compromised Japanese websites for command-and-control, and follow-on tooling for reconnaissance and credential theft, while introducing distinct behavior such as process hollowing into explorer.exe or LSASS.exe and steganography-based payload delivery through image files. Researchers also described an xxmm builder that can generate 32-bit and 64-bit payloads, configure persistence, and support PHP tunnel communications.
Technical details from prior JPCERT/JSAC analysis show the broader xxmm remote access trojan, also known as Minzen and associated with BRONZE BUTLER, supports command-and-control over HTTP, TCP, UDP, and ICMP and protects traffic with custom Base64 encoding, LZNT1 compression, and RC4 or RSA-wrapped session keys. The malware exposes a full remote administration feature set, including file operations, remote shell access, PowerShell execution, process creation, and plugin-based post-compromise activity, and has been observed using Mimikatz for credential dumping. Together, the reports indicate that Wali and ShadowWali remain active and capable backdoors designed for stealthy persistence, credential access, and lateral movement inside Japanese victim environments.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
A JPCERT/JSAC presentation in 2019 analyzed xxmm/Minzen, detailing its installer, encrypted resources, hardcoded configuration, and command-and-control over HTTP/S, TCP, UDP, and ICMP. It also described capabilities such as file operations, remote shell, PowerShell execution, and process creation.
The JPCERT/JSAC presentation assessed the BRONZE BUTLER threat actor as seemingly inactive since early 2018. The same presentation linked xxmm, also known as Minzen, to BRONZE BUTLER operations.
The JPCERT/JSAC presentation noted that several Datper variants were observed from November 2017. It said these variants changed to use a modified RC4 initialization.
Cybereason said the xxmm backdoor family has targeted Japanese businesses and organizations since 2015. The activity included use of large binaries, compromised Japanese websites for command-and-control, and payloads for reconnaissance and credential theft.
Cybereason reported that the xxmm builder sample xxmm2_build.exe was compiled in January 2015. The builder supported features including persistence options, process injection targets, PHP tunnel communications, and steganography-based payload hiding in image files.
Cybereason found an xxmm payload in scommand.txt on a compromised Japanese website and decrypted it to rr2E9E.tmp. The decrypted payload's PDB path pointed to the shadowWalker project, supporting the ShadowWali linkage.
Cybereason analyzed ShadowWali as a member of the xxmm backdoor family and assessed it as either an earlier version of Wali or a closely related sibling. The report also linked ShadowWali and Wali to the same developer identified as user "123" through PDB paths.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.