familyunclassified-js-cjk-stego-dropperconfidencehighupdated2026-08-19

unclassified-js-cjk-stego-dropper

A JScript dropper family that encodes a raw PE payload inside CJK Unified Ideograph or Hangul Syllable character strings assigned to a JavaScript dictionary. The outer script is saved as UTF-16 LE with CRLF line terminators, masquerading as a PDF or shipping document via double-extension or descriptive filename.

Technical Summary

The malware uses a custom steganography engine where each byte of the inner .NET assembly is encoded as a Unicode character via a fixed offset from the base code point. Two encoding schemes observed:

  • CJK Unified Ideographs (byte = charcode - 0x3400) — used by sample 0de6482c, 384 dictionary entries.
  • Hangul Syllables (byte = charcode - 0xAC00) — used by sample 7129076f, 347 dictionary entries, plus a fallback CJK stream-cipher path.

At runtime, a for loop walks an order array, concatenates the encoded blocks, decodes them, and assigns the result to a process-scoped environment variable via WScript.Shell.Environment("Process"). A PowerShell stage then reconstructs the inner PE in-memory.

Inner Payload

The reconstructed payload is a .NET Framework 4.x PE32+ x64 GUI assembly with semantic English obfuscation of all type and method names. Sample 0de6482c (385,024 bytes) imports URLDownloadToFileW (urlmon.dll), OleGetClipboard/OleFlushClipboard, and SHA256.ComputeHash. Sample 7129076f (349,696 bytes) has no manifest resources and references System.Xml, System.Configuration — suggesting configurable C2, but no static network indicators.

Capabilities

  • cjk-unicode-steganography-pe-dropper
  • hangul-syllable-steganography-pe-dropper
  • environment-variable-payload-staging
  • wscript-shell-powershell-spawn
  • semantic-english-name-obfuscation
  • dotnet-assembly-reflective-loading
  • double-path-resilient-delivery
  • urlmon-downloader
  • clipboard-manipulation
  • sha256-hashing
  • xslt-jscript-extension-execution
  • conhost-headless-powershell-spawn
  • javascript-obfuscator-string-array-wrapper
  • purchase-order-spam-lure-delivery

Siblings

Three confirmed siblings. Same actor, evolved tooling.

Observed Samples

SHA-256 Filename Date Notes
0de6482c... RFQ rfq_pdf.js 2026-07-26 First observed; RFQ social-engineering lure. CJK Unified Ideograph encoding (byte = charcode - 0x3400) with 384-entry dictionary. ^[/intel/analyses/0de6482c69377a127b91aa9c28d24981b656be44a9181a83c5b014a933987216.html]
7129076f... revised Shipping document BL PL and comercial Invoice.js 2026-08-06 Second confirmed sibling. Hangul Syllable encoding (byte = charcode - 0xAC00) with 347-entry dictionary, plus fallback CJK stream-cipher path. Inner .NET assembly v4.9.7732.6353, semantic English obfuscation. ^[/intel/analyses/7129076f2b648b20cbd7b35eb8612ba4315be053ebcb5fa852b689f1ef72deed.html]
eba13078... Purchase Order 386761 SN 0002842747 DOC.js 2026-08-19 Third confirmed sibling. CJK Unified Ideograph encoding (byte = charcode - 0x4E00) with 381-entry dictionary. Novel XSLT JScript extension execution path and conhost.exe --headless window suppression. Inner .NET assembly 379,392 bytes, SHA-256 5b931001.... ^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300.html]

References