AcidBox

Aliases: MagicScroll

First seen
2017-01-01 00:00:00
Malware type
exploit-kit, rootkit
Family
Malware family
Profile updated
2026-07-07 13:03:48

Targeted industries: government-and-public-sector

Targeted regions: country_code:ru

Context

Unit42 found AcidBox in February 2019 and describes it as a malware family used by an unknown threat actor in 2017 against Russian entities, as stated by Dr.Web. It reused and improved an exploit for VirtualBox previously used by Turla. The malware itself is a modular toolkit, featuring both usermode and kernelmode components and anti-analysis techniques such as stack-based string obfuscation or dynamic XOR-encoded API usage.

Detection coverage

  • 4 YARA rules

Detection rules

  • TRELLIX_ARC_APT_Acidbox_Kernelmode_Module (yara-rule)
  • TRELLIX_ARC_APT_Acidbox_Main_Module_Dll (yara-rule)
  • TRELLIX_ARC_APT_Acidbox_Ssp_Dll_Module (yara-rule)
  • MALPEDIA_Win_Acidbox_Auto (yara-rule)

Reports & references

  • Kaspersky — 97937 (report)
  • Cisco Talos — Attribution Puzzle (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Acidbox (report)
  • Palo Alto Unit 42 — Acidbox Rare Malware (report)
  • epicturla.com — Acidbox Clustering (report)

External references