Chasing an Angry Spark

April 15, 2026, 5:28 p.m.

Description

In spring 2022, a highly sophisticated backdoor named AngrySpark was discovered on a single machine in the United Kingdom. The malware employed a three-stage architecture: a DLL masquerading as a Windows Task Scheduler component, a custom virtual machine interpreter running bytecode instructions, and a beacon that profiles systems while disguising C2 communications as PNG image requests. The malware featured VM-based obfuscation, dual encrypted C2 channels using RSA-4096 and XXTEA encryption, direct syscalls bypassing usermode hooks, hypervisor detection, and CET-aware anti-analysis capabilities. It operated for approximately one year with active maintenance visible through syscall table updates and configuration changes between May 2022 and January 2023. The infrastructure expired in mid-2023 and the operation ceased, with no additional samples or victims identified despite the significant engineering effort invested in its development.

Date

  • Created: April 15, 2026, 9:21 a.m.
  • Published: April 15, 2026, 9:21 a.m.
  • Modified: April 15, 2026, 5:28 p.m.

Indicators

  • 491870264fa2d666fb8859508a6a44b80bcb868e2f43c00f03199df2651c757d
  • 9c492a39823aa0ff14f3131a2346f833827a1c423e77dcc9682bb939aea0e215
  • 96883abd45eca3f076f1d5e2a9e75e37b588a37a99fe42ec4bedd34f7926760e
  • 20f19a37e17772c38b6f89af40fa941d55bad9ffcf3b3382206a0cadfa937025
  • 185.151.31.111
  • 185.151.31.6
  • https://pick.storewebzone.net/assets/static/img/I4o8Pp_41.png
  • https://pick.storewebzone.net/prod/vUcLWuZF/8363/asb2dz_1dd4.php

Attack Patterns

Additional Informations

  • comp.id
  • s13035516.server-sys.com
  • pick.storewebzone.net
  • server-sys.com
  • storewebzone.net