logo

Cmstar Downloader: Lurid and Enfal's New Cousin - Palo Alto Networks BlogPalo Alto Networks Blog

ID: fa61e510-5502-4a75-be83-cba7ccca1fb0

STIX ID: report--fa61e510-5502-4a75-be83-cba7ccca1fb0

Threat Score

70/100

Uploaded: 2026-08-07

Published Date: 2015-05-29

Last Modified Date: 2015-05-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 presents a technical analysis of the Cmstar downloader used in spear-phishing campaigns, describing an unusual method for manually building the Import Address Table via character/offset mappings, a hashing routine to detect AV processes (notably Kaspersky's avp.exe), encrypted configuration and shellcode that communicates with multiple C2 domains, registry persistence artifacts, and substantial infrastructure overlap tying Cmstar to Lurid/Enfal and Cmwhite; the report includes numerous IOCs (filenames, hashes, domains), delivery document metadata (MNKit and Tran Duy Linh toolkits), and a Yara rule for detection.