fused-string-api-decoding
Go malware anti-static technique observed across the lummastealer, acrstealer, and orderreshop clusters. Windows API names are fused with their parent DLL names into single indivisible .rdata strings (e.g., kernel32.dllVirtualAlloc), then sliced at runtime via index arithmetic to recover the separate DLL and API components. This defeats naive string extraction tools that expect kernel32.dll and VirtualAlloc as distinct tokens.
Detection
- Search for long
.rdatastrings containing known DLL prefixes (kernel32.dll,ntdll.dll,advapi32.dll) immediately concatenated with API names. - Look for
stringsoutput where DLL+API pairs appear as a single token with no delimiter. - In Go binaries, trace
runtime.sliceStringorstrings.Indexcalls insidemain.*wrappers.
Observed In
- lummastealer siblings
e03dd36f,040e0d76,90d54589,c25d9423^[/intel/analyses/e03dd36f22e24a323f8db11ba3a220786ea14c5617538b5433911e5a6d1f66a3.html] - acrstealer cluster (shared code reuse)