EASYNIGHT

Malware type
loader
Profile updated
2026-07-07 12:56:54

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

FireEye describes EASYNIGHT is a loader observed used with several malware families, including HIGHNOON and HIGHNOON.LITE. The loader often acts as a persistence mechanism via search order hijacking. Examples include a patched bcrypt.dll with no other modification than an additional import entry, in the observed case "printwin.dll!gzwrite64" (breaking the file signature).

Reports & references

  • Trend Micro — Winnti Abuses Github (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Easynight (report)
  • Mandiant — Pdfproxy (report)

External references