unclassified-js-cjk-stego-dropper
A JScript dropper family that encodes a raw PE payload inside CJK Unified Ideograph or Hangul Syllable character strings assigned to a JavaScript dictionary. The outer script is saved as UTF-16 LE with CRLF line terminators, masquerading as a PDF or shipping document via double-extension or descriptive filename.
Technical Summary
The malware uses a custom steganography engine where each byte of the inner .NET assembly is encoded as a Unicode character via a fixed offset from the base code point. Two encoding schemes observed:
- CJK Unified Ideographs (
byte = charcode - 0x3400) — used by sample0de6482c, 384 dictionary entries. - Hangul Syllables (
byte = charcode - 0xAC00) — used by sample7129076f, 347 dictionary entries, plus a fallback CJK stream-cipher path.
At runtime, a for loop walks an order array, concatenates the encoded blocks, decodes them, and assigns the result to a process-scoped environment variable via WScript.Shell.Environment("Process"). A PowerShell stage then reconstructs the inner PE in-memory.
Inner Payload
The reconstructed payload is a .NET Framework 4.x PE32+ x64 GUI assembly with semantic English obfuscation of all type and method names. Sample 0de6482c (385,024 bytes) imports URLDownloadToFileW (urlmon.dll), OleGetClipboard/OleFlushClipboard, and SHA256.ComputeHash. Sample 7129076f (349,696 bytes) has no manifest resources and references System.Xml, System.Configuration — suggesting configurable C2, but no static network indicators.
Capabilities
cjk-unicode-steganography-pe-dropperhangul-syllable-steganography-pe-dropperenvironment-variable-payload-stagingwscript-shell-powershell-spawnsemantic-english-name-obfuscationdotnet-assembly-reflective-loadingdouble-path-resilient-deliveryurlmon-downloaderclipboard-manipulationsha256-hashingxslt-jscript-extension-executionconhost-headless-powershell-spawnjavascript-obfuscator-string-array-wrapperpurchase-order-spam-lure-delivery
Siblings
Three confirmed siblings. Same actor, evolved tooling.
Observed Samples
| SHA-256 | Filename | Date | Notes |
|---|---|---|---|
0de6482c... |
RFQ rfq_pdf.js |
2026-07-26 | First observed; RFQ social-engineering lure. CJK Unified Ideograph encoding (byte = charcode - 0x3400) with 384-entry dictionary. ^[/intel/analyses/0de6482c69377a127b91aa9c28d24981b656be44a9181a83c5b014a933987216.html] |
7129076f... |
revised Shipping document BL PL and comercial Invoice.js |
2026-08-06 | Second confirmed sibling. Hangul Syllable encoding (byte = charcode - 0xAC00) with 347-entry dictionary, plus fallback CJK stream-cipher path. Inner .NET assembly v4.9.7732.6353, semantic English obfuscation. ^[/intel/analyses/7129076f2b648b20cbd7b35eb8612ba4315be053ebcb5fa852b689f1ef72deed.html] |
eba13078... |
Purchase Order 386761 SN 0002842747 DOC.js |
2026-08-19 | Third confirmed sibling. CJK Unified Ideograph encoding (byte = charcode - 0x4E00) with 381-entry dictionary. Novel XSLT JScript extension execution path and conhost.exe --headless window suppression. Inner .NET assembly 379,392 bytes, SHA-256 5b931001.... ^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300.html] |
References
- unattributed — umbrella entity for low-confidence singletons
- jscript-environment-variable-staging — technique page for the env-var payload staging chain
- cjk-unicode-steganography — concept page for byte-in-CJK encoding
- hangul-syllable-steganography — technique page for Hangul Syllable encoding