SodaMaster
MITRE ATT&CK: S0627 View on attack.mitre.org
Aliases: DARKTOWN, dfls, DelfsCake, HEAVYPOT, SodaMaster
- First seen
- 2020-01-01 00:00:00
- Malware type
- downloader, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2026-08-30 06:26:55
- Profile updated
- 2026-07-07 13:02:17
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Targeted regions: country_code:jp country_code:us country_code:gb
Context
SodaMaster is a fileless malware used by menuPass to download and execute payloads since at least 2020.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to SodaMaster (S0627). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 94005d980a56734e86eecfd48efe3f794a549307b3902472a8e59cf79833b042.bin.exe | 2026-08-30 | 2 |
| file sample | file | 2026-08-19 | 2 |
| file sample | 47c407f3f99e7b5c65fcfb454f10828c08f431884336ce5c5c90c9b3a903d819.bin.exe | 2026-07-22 | 2 |
| file sample | 49dab8647d7a28c0b75ecb99e06f70ae3c9bc7ed2e91b2c0ab2ce769891c83c4 | 2026-06-16 | 3 |
Detection coverage
- 1 YARA rules
- 246 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Native API (attack-pattern)
- System Checks (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Time Based Checks (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Process Discovery (attack-pattern)
- Query Registry (attack-pattern)
Used by threat actors
- menuPass (threat-actor)
Detection rules
- MALPEDIA_Win_Sodamaster_Auto (yara-rule)
Reports & references
- ESET — Operation Fishmedley (report)
- secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
- jsac.jpcert.or.jp — Jsac2021 202 Niwa Yanagishita En (report)
- Kaspersky — 101967 (report)
- jsac.jpcert.or.jp — Jsac2022 9 Yanagishita Tamada Nakatsuru Ishimaru En (report)
- Broadcom/Symantec — Cicada Apt10 China Ngo Government Attacks (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sodamaster (report)
- bleepingcomputer.com — Chinese Hackers Abuse Vlc Media Player To Launch Malware Loader (report)
- Kaspersky — 101519 (report)
- MITRE ATT&CK — S0627 (report)