typetechniqueconfidencemediumcreated2026-08-31updated2026-08-31obfuscationgolangevasionanti-static

fused-string-api-decoding

Go malware anti-static technique observed across the lummastealer, acrstealer, and orderreshop clusters. Windows API names are fused with their parent DLL names into single indivisible .rdata strings (e.g., kernel32.dllVirtualAlloc), then sliced at runtime via index arithmetic to recover the separate DLL and API components. This defeats naive string extraction tools that expect kernel32.dll and VirtualAlloc as distinct tokens.

Detection

  • Search for long .rdata strings containing known DLL prefixes (kernel32.dll, ntdll.dll, advapi32.dll) immediately concatenated with API names.
  • Look for strings output where DLL+API pairs appear as a single token with no delimiter.
  • In Go binaries, trace runtime.sliceString or strings.Index calls inside main.* wrappers.

Observed In

  • lummastealer siblings e03dd36f, 040e0d76, 90d54589, c25d9423 ^[/intel/analyses/e03dd36f22e24a323f8db11ba3a220786ea14c5617538b5433911e5a6d1f66a3.html]
  • acrstealer cluster (shared code reuse)

Related