
Spring Dragon Hides SQL Implant in Signed Netease Emulator, Fools All 76 AV Engines
A trojanised MuMuPlayer Android emulator binary carrying a valid, unrevoked Netease code-signing certificate has achieved complete antivirus evasion while embedding SKIP-2.0 SQL Server authentication-bypass hook patterns. CTX Team has linked the payload to Spring Dragon command-and-control infrastructure spanning four domains across Cloudflare and AWS, targeting education and technology sector organisations.
A 24-megabyte Windows executable presenting as the legitimate Netease MuMuPlayer Android emulator has cleared every antivirus engine that examined it — all 76 of them — while simultaneously triggering a YARA rule identifying byte patterns consistent with the SKIP-2.0 SQL Server authentication-bypass implant. The binary carries a valid, unrevoked DigiCert-rooted code-signing certificate issued to Netease Interactive Entertainment Pte.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read