Skip to content

Sakula

Sakula, also known as Sakurel and VIPER, is a Windows remote access trojan associated with targeted intrusions attributed to Chinese threat activity, including reporting linking it to Deep Panda and to intrusions referenced in U.S.

Profile source: Mallory opens in a new tab

Sakula

Family profile

Sakula, also known as Sakurel and VIPER, is a Windows remote access trojan associated with targeted intrusions attributed to Chinese threat activity, including reporting linking it to Deep Panda and to intrusions referenced in U.S. indictments involving Chinese operators. It was active in observed operations from at least 2012 through 2015 and was notably associated with strategic web compromise activity exploiting CVE-2014-0322 as well as installer-based delivery masquerading as legitimate software.

Sakula provides interactive remote access and post-compromise control, including remote shell capability, file upload and download, execution of additional payloads, and general command execution. It communicates with command-and-control infrastructure over HTTP using GET and POST requests and obfuscates traffic, embedded strings, and stored resources with single-byte XOR encoding. Samples have also been observed invoking cmd.exe and rundll32 during execution and cleanup.

A defining tradecraft feature of Sakula is DLL side-loading. Multiple variants abuse legitimate signed Windows applications and third-party software components to load malicious DLLs, including known use of signed Kaspersky and McAfee components. This technique supports defense evasion and execution while blending into trusted software activity. Some variants also include User Account Control bypass code for both 32-bit and 64-bit Windows systems, indicating support for privilege escalation during installation or follow-on execution.

Persistence is commonly achieved through Windows Registry Run entries, while some samples install themselves as Windows services. Certain variants perform cleanup by deleting temporary artifacts after installation. The malware’s code base remained relatively stable across multiple years of observed use, suggesting it was an effective and reusable espionage platform for targeted operations against organizations in multiple sectors.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Privilege Escalation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 1, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
1 IP / 1 hostnames

Leading locations

  • TH1
  • US1

Leading providers

  • AIS Fibre1
  • Amazon.com, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
APT41

The indictment was filed by US federal attorneys... it accuses ten Chinese individuals... According to the indictment... they used the Sakula, PlugX, and Winnti malware in the different organizations.

APT19

Matt Dahl, “I am Ironman: DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors,” CrowdStrike, November 24, 2014

Exploited software

Vulnerabilities linked to Sakula

1 CVEs

MITRE ATT&CK

Sakula in ATT&CK

26 distinct techniques

Reporting

Research mentioning Sakula

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

Oct 21
Eset Welivesecurity

Winnti Group's skip-2.0: A Microsoft SQL Server backdoor

ESET reported that the Winnti Group used a previously unanalyzed passive backdoor called PortReuse and tied it to a broader malware arsenal that also includes updated ShadowPad variants and a VMProtect-based launcher. PortReuse injects into processes already listening on common ports, waits for a magic packet, and covertly enables attacker control while forwarding legitimate traffic, helping it blend into normal network activity. The launcher decrypts either PortReuse or ShadowPad payloads with RC5 keys derived from the victim machine’s volume serial number, a technique ESET said reinforced the technical links across the toolset. The research connected multiple high-profile software supply-chain compromises—including CCleaner, NetSarang, Asus ShadowHammer, and several 2018 compromised games and software incidents—to the same broader Winnti ecosystem through shared tooling, cryptography, and tradecraft. ESET also said some of the 2018 third-stage payloads were XMRig Monero miners, indicating cryptocurrency mining as one operational objective. With assistance from Censys, the company identified eight Internet-facing systems matching PortReuse’s HTTP signature at a major Asian mobile hardware and software manufacturer and said it notified the victim.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.