sRDI

Aliases: DAVESHELL

Malware type
loader
Family
Malware family
Profile updated
2026-07-07 13:14:08

Context

sRDI allows for the conversion of DLL files to position independent shellcode. It attempts to be a fully functional PE loader supporting proper section permissions, TLS callbacks, and sanity checks. It can be thought of as a shellcode PE loader strapped to a packed DLL.

Reports & references

  • cloud.google.com — Unc4393 Goes Gently Into Silentnight (report)
  • Mandiant — Dprk Whatsapp Phishing (report)
  • Mandiant — Apt29 Evolving Diplomatic Phishing (report)
  • ESET — Lazarus Luring Employees Trojanized Coding Challenges Case Spanish Aerospace Company (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Srdi (report)
  • github.com — Srdi (report)

External references