C&CMembers
C&C

Spring Dragon Hides SQL Implant in Signed Netease Emulator, Fools All 76 AV Engines

A trojanised MuMuPlayer Android emulator binary carrying a valid, unrevoked Netease code-signing certificate has achieved complete antivirus evasion while embedding SKIP-2.0 SQL Server authentication-bypass hook patterns. CTX Team has linked the payload to Spring Dragon command-and-control infrastructure spanning four domains across Cloudflare and AWS, targeting education and technology sector organisations.

May 26, 2026, 10:47 (UTC+9)Last seenMay 26, 2026Severity87ByCTX TeamActorSpring DragonLotus BlossomIOC7MITRE4

A 24-megabyte Windows executable presenting as the legitimate Netease MuMuPlayer Android emulator has cleared every antivirus engine that examined it — all 76 of them — while simultaneously triggering a YARA rule identifying byte patterns consistent with the SKIP-2.0 SQL Server authentication-bypass implant. The binary carries a valid, unrevoked DigiCert-rooted code-signing certificate issued to Netease Interactive Entertainment Pte.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence