← Back to SOC feed Coverage →

Armadillov220b1

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-18T23:00:01Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets the Armadillo malware family, a known threat actor associated with the APT28 (Cozy Bear) group, by identifying specific code patterns or strings indicative of its presence in memory or on disk. Proactively hunting for this signature allows the SOC to detect early-stage espionage or reconnaissance activities before the adversary establishes persistence or executes further post-exploitation actions within the Azure environment.

YARA Rule

rule Armadillov220b1
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 55 8B EC 6A FF 68 30 12 41 00 68 A4 A5 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 58 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar