APT29_Informe LAB52- EasterBunny_Complete.pdf
ID: 77d1300a-79e4-4b8d-811c-b7436c4d71fe
STIX ID: report--77d1300a-79e4-4b8d-811c-b7436c4d71fe
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2026-02-02
Last Modified Date: 2026-02-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
S2GRUPO / LAB52 provide a detailed technical analysis of 'EasterBunny', a highly sophisticated, multi-layer implant attributed to APT29. The report documents a Matryoshka-style execution chain (wrapper → code block #1 → code block #2 → final payload), per-host key derivation making binaries usable only on the infected machine, strong OPSEC and memory cleanup, registry persistence with encrypted configuration and credential storage, an HTTP-based C2 protocol using steganographic cookie fields and JavaScript payloads, and modular post-exploitation capabilities (including DCSync modules). Detection artefacts such as YARA rules, NIDS signatures and regex lists are provided to aid defenders.
