Last seven days
- First activity
- Sep 1, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 1 hostnames
Sakula, also known as Sakurel and VIPER, is a Windows remote access trojan associated with targeted intrusions attributed to Chinese threat activity, including reporting linking it to Deep Panda and to intrusions referenced in U.S.
Profile source: Mallory opens in a new tabSakula
Sakula, also known as Sakurel and VIPER, is a Windows remote access trojan associated with targeted intrusions attributed to Chinese threat activity, including reporting linking it to Deep Panda and to intrusions referenced in U.S. indictments involving Chinese operators. It was active in observed operations from at least 2012 through 2015 and was notably associated with strategic web compromise activity exploiting CVE-2014-0322 as well as installer-based delivery masquerading as legitimate software.
Sakula provides interactive remote access and post-compromise control, including remote shell capability, file upload and download, execution of additional payloads, and general command execution. It communicates with command-and-control infrastructure over HTTP using GET and POST requests and obfuscates traffic, embedded strings, and stored resources with single-byte XOR encoding. Samples have also been observed invoking cmd.exe and rundll32 during execution and cleanup.
A defining tradecraft feature of Sakula is DLL side-loading. Multiple variants abuse legitimate signed Windows applications and third-party software components to load malicious DLLs, including known use of signed Kaspersky and McAfee components. This technique supports defense evasion and execution while blending into trusted software activity. Some variants also include User Account Control bypass code for both 32-bit and 64-bit Windows systems, indicating support for privilege escalation during installation or follow-on execution.
Persistence is commonly achieved through Windows Registry Run entries, while some samples install themselves as Windows services. Certain variants perform cleanup by deleting temporary artifacts after installation. The malware’s code base remained relatively stable across multiple years of observed use, suggesting it was an effective and reusable espionage platform for targeted operations against organizations in multiple sectors.
C2 tracking
Derp observations, rolling seven-day window
Samples
1af57b30c55808916679ac4764b54834e202f78ff8da9dabcd33addbf0e77440 61dca093868c43136f3507eea4808440e16a9cbe83b1934cf0db40872a721a42 a32aa634f85db728ae3b29dff440b840c74b19ede0a852be91872f9286da7979 c2f33aa2572a97a9bd6628b80286753b34f4338d2704fe043582cacfb049b231 fa4eecf1c3bf880bab60f6e70ec507903d42649cfd8e5ff5b98d435079843612 0bb6855d2a6ae51f66f11a9633aad80835b3cec7612fcfc834b602a506433cdc 7251c40a7f8ba5051733616ba96693438da65a873803fe1f7b330feb9ed4873c 7a2f238bd3b8614ec5fe4ed6757bbdf16bdbad266c193c911747176b8eb6f7a6 8212db79950ff6c5d5d04425a293d858b9af858c770101c1b9184be234ebd798 84c00741099c035fb5059cdb3da09afdc6b64d3b6433bbaca4e4a454ccff239a Reported operators
The indictment was filed by US federal attorneys... it accuses ten Chinese individuals... According to the indictment... they used the Sakula, PlugX, and Winnti malware in the different organizations.
Matt Dahl, “I am Ironman: DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors,” CrowdStrike, November 24, 2014
Exploited software
MITRE ATT&CK
Reporting
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
ESET reported that the Winnti Group used a previously unanalyzed passive backdoor called PortReuse and tied it to a broader malware arsenal that also includes updated ShadowPad variants and a VMProtect-based launcher. PortReuse injects into processes already listening on common ports, waits for a magic packet, and covertly enables attacker control while forwarding legitimate traffic, helping it blend into normal network activity. The launcher decrypts either PortReuse or ShadowPad payloads with RC5 keys derived from the victim machine’s volume serial number, a technique ESET said reinforced the technical links across the toolset. The research connected multiple high-profile software supply-chain compromises—including CCleaner, NetSarang, Asus ShadowHammer, and several 2018 compromised games and software incidents—to the same broader Winnti ecosystem through shared tooling, cryptography, and tradecraft. ESET also said some of the 2018 third-stage payloads were XMRig Monero miners, indicating cryptocurrency mining as one operational objective. With assistance from Censys, the company identified eight Internet-facing systems matching PortReuse’s HTTP signature at a major Asian mobile hardware and software manufacturer and said it notified the victim.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.