Last seven days
- First activity
- Aug 7, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 1 hostnames
Sakula is a Windows malware family, also referred to as Sakurel and Viper, that functions as a backdoor/RAT with command-and-control over HTTP using GET and POST requests.
Profile source: Mallory opens in a new tabSakula
Sakula is a Windows malware family, also referred to as Sakurel and Viper, that functions as a backdoor/RAT with command-and-control over HTTP using GET and POST requests. Reported samples encode C2 traffic with single-byte XOR keys. Sakula has been observed using DLL side-loading for execution, including abuse of digitally signed binaries such as Kaspersky Anti-Virus and McAfee Outlook Scan About Box to load malicious DLLs. It contains UAC bypass code for both 32-bit and 64-bit systems, can install itself as a Windows service for persistence, and uses cmd.exe to execute DLLs via rundll32 as well as to delete temporary files and perform cleanup. Some reporting also notes reverse shell capability. The malware is notably linked in reporting to the 2015 U.S. Office of Personnel Management (OPM) breach; in 2017, Chinese national Yu Pingan was arrested on charges of providing Sakula used in the OPM data breach and other cyber intrusions. High-confidence behavioral indicators mentioned in the content include HTTP-based C2, single-byte XOR-obfuscated traffic, DLL side-loading via signed applications, service-based persistence, rundll32 execution through cmd.exe, temporary file deletion, and embedded UAC bypass functionality.
C2 tracking
Derp observations, rolling seven-day window
Samples
035e3c98415a2d3e15a8f3586f492dbaa9d2ed1db06afebe4f78511f2fa3e018 0c066e9a7ae3fc975ac21844de0841d8dd5df656e567dc294add830c3f717b74 2347896c39cd3caa6584d4f428a70a4cdcea971312ba93bb32dde081b0d4c6e1 bf72ea0b3b6ef4dc48a4abe18a7a17a6fe6808b076921b64845c9494df6040f2 df66ddd860a467f05ba355699615ada3f76c61560a29969da21276d364f568e7 04bbb2229d812b5b196b55aaae247e2adf8759b19a2f5411fbe670ace8147121 2946b931ce28aabbb03881f8671892a6c6a4b9a8fad67b8a0fb75497de27e439 531ea9fa3b96cbed053949671ebf072a988e1a9c7cbcae8b19a9a1c7e3cea93c 7cb404194fa2624a2a07ace0fd4f56afb94a977b9e891614514a3174cbb2e13d fde909a911da8ffba39aede49afe7dae27f720585746d70bb12d10962c859df6 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.