Detailed Analysis of SIGNBT Malware Cluster
2026-07-30 • S2W •
https://s2w.medium.com/detailed-analysis-of-signbt-malware-cluster-504fc3ab4ecf
S2W analyzed three malware clusters targeting South Korea that combine legitimate-process abuse, DLL side-loading, encrypted payload staging, and manual PE mapping. Two chains deploy SIGNBT v0.0.1 or v1.2 from service-registry blobs or embedded containers, while a third uses a masquerading `mfplat.dll` to decrypt an external payload identified through command-line data. SIGNBT supports system discovery, command execution, file and process control, screen capture, memory-resident modules, and encoded HTTP C2 communication. Detection should correlate abnormal DLL loads, service-registry blob access, decryption followed by executable memory allocation, and SIGNBT protocol behavior.