menomoushop
Overview
Windows infostealer family delivered as a Go-compiled PE64 binary. First observed in the local corpus via MalwareBazaar with OpenCTI tags menomou-shop, remusstealer, and sunwukong. Signed with Authenticode DV certificates (observed: Go Daddy CA G2, leaf CN maybe.us). No CAPE detonation results yet; all characterization is static.
Build Stack
- Language: Go 1.25.4^[/intel/analyses/3aca18df0426522e0c301a55dae3d892b2009719854207b4bae45f4c94403c9f.html]
- Arch: PE32+ x86-64, Windows GUI subsystem
- Linker flags:
-H=windowsgui(no console window) - Stripping:
.symtabretained (unstripped) — rare for production malware; gives full function and type recovery - Signing: Authenticode PKCS#7 embedded in
IMAGE_DIRECTORY_ENTRY_SECURITY - Obfuscation:
mainpackage function names randomized (8–16 character alphanumeric). No control-flow flattening or string encryption observed statically. - Crypto primitives: AES (S-Box in
.rdata), SHA256, HMAC-SHA2-256, ChaCha20 random (Go FIPS 140-3 module) — all standard library.
Capabilities
go-pe64-authenticode-signedtls-encrypted-c2-inferredaes-runtime-cryptofunction-name-randomizationruntime-jitter-delay(math/rand.Intn loops observed)credential-exfiltration-inferredunstripped-symbol-table
Deploy / TTPs
| Technique | ID | Evidence |
|---|---|---|
| Encrypted Channel | T1573.001 | AES S-Box / crypto/tls in .rdata^[sample 3aca18df/binwalk.txt] |
| Application Layer Protocol | T1071.001 | net/http, crypto/tls package strings^[sample 3aca18df/strings.txt] |
| Obfuscated Files or Information | T1027 | Function-name randomization (not string encryption)^[raw/analyses/3aca18df0426522e0c301a55dae3d892b2009719854207b4bae45f4c94403c9f/r2:sym.main.main] |
Variants / Aliases
menomou-shop— MalwareBazaar / OpenCTI labelremusstealer— co-labeled on multiple siblings in corpussunwukong— filename-themed label (sunwukongs.exeobserved)
Notable Analyses
- /intel/analyses/3aca18df0426522e0c301a55dae3d892b2009719854207b4bae45f4c94403c9f.html — 3aca18df, Go 1.25.4, signed CN
maybe.us, static-only
Related
- golang-stealer-build-pattern — shared Go infostealer build artefacts
- remusstealer — sibling label cluster (no dedicated entity page yet)