Chasing an Angry Spark
April 15, 2026, 5:28 p.m.
Description
In spring 2022, a highly sophisticated backdoor named AngrySpark was discovered on a single machine in the United Kingdom. The malware employed a three-stage architecture: a DLL masquerading as a Windows Task Scheduler component, a custom virtual machine interpreter running bytecode instructions, and a beacon that profiles systems while disguising C2 communications as PNG image requests. The malware featured VM-based obfuscation, dual encrypted C2 channels using RSA-4096 and XXTEA encryption, direct syscalls bypassing usermode hooks, hypervisor detection, and CET-aware anti-analysis capabilities. It operated for approximately one year with active maintenance visible through syscall table updates and configuration changes between May 2022 and January 2023. The infrastructure expired in mid-2023 and the operation ceased, with no additional samples or victims identified despite the significant engineering effort invested in its development.
Tags
Date
- Created: April 15, 2026, 9:21 a.m.
- Published: April 15, 2026, 9:21 a.m.
- Modified: April 15, 2026, 5:28 p.m.
Indicators
- 491870264fa2d666fb8859508a6a44b80bcb868e2f43c00f03199df2651c757d
- 9c492a39823aa0ff14f3131a2346f833827a1c423e77dcc9682bb939aea0e215
- 96883abd45eca3f076f1d5e2a9e75e37b588a37a99fe42ec4bedd34f7926760e
- 20f19a37e17772c38b6f89af40fa941d55bad9ffcf3b3382206a0cadfa937025
- 185.151.31.111
- 185.151.31.6
- https://pick.storewebzone.net/assets/static/img/I4o8Pp_41.png
- https://pick.storewebzone.net/prod/vUcLWuZF/8363/asb2dz_1dd4.php
Additional Informations
- comp.id
- s13035516.server-sys.com
- pick.storewebzone.net
- server-sys.com
- storewebzone.net