typeentityconfidencemediumcreated2026-08-04updated2026-08-04malware-familypec2defense-evasiondiscoveryloader

Wraith

A Windows PE32 malware family characterized by a custom companion-file XOR decryption stub, system-information harvesting, and raw-socket C2 surface. The MalwareBazaar/OpenCTI label wraith co-occurs with the prometei botnet family in broader threat-intel feeds, but technical evidence linking the two is sparse — treat as separate families until cluster confirmation.

Build Stack

  • PE32 GUI, x86, 6 sections
  • MajorLinkerVersion 6.0 (retro toolchain) with forged or recent timestamps
  • RWX section flags on .stub and .text (self-modifying / encrypted payload) ^[sample 0ab9a570/pefile.txt]
  • Unsigned; no Authenticode certificate
  • Heavy .data section inflation: ~24 MB virtual size, ~16 KB raw (encrypted payload staging)

Deploy / TTPs

TTP ID Evidence
System Information Discovery T1082 systeminfo execution via CreateProcessA ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]
Network Service Discovery T1046 ping 8.8.8.8 connectivity probe ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]
Obfuscated Files or Information T1027 Rolling XOR decryption with external companion key ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]
Access Token Manipulation T1134.001 OpenProcessToken → AdjustTokenPrivileges ^[sample 0ab9a570/pefile.txt]
Command and Control T1071.001 Full raw-socket WSOCK32 import surface (no hardcoded C2 strings recovered) ^[sample 0ab9a570/pefile.txt]

Capabilities

  • companion-file-key-decryption
  • rolling-xor-section-decryption
  • systeminfo-harvesting
  • connectivity-probe-ping
  • raw-tcp-c2-socket
  • token-privilege-escalation
  • rwx-section-self-modifying
  • filesystem-gate-anti-sandbox

Notable Analyses

  • 0ab9a570 — Custom XOR companion-key PE32 stub, systeminfo harvesting, raw-socket C2 surface. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]

Related

Attribution

No clear actor attribution. The masquerade string PaiAuganMai does not map to known legitimate software. The retro linker version (v6.0) with a 2025 timestamp suggests either deliberate toolchain selection or timestamp forgery.