This YARA rule targets the Armadillo malware family, a known threat actor associated with the APT28 (Cozy Bear) group, by identifying specific code patterns or strings indicative of its presence in memory or on disk. Proactively hunting for this signature allows the SOC to detect early-stage espionage or reconnaissance activities before the adversary establishes persistence or executes further post-exploitation actions within the Azure environment.
rule Armadillov220b1
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 30 12 41 00 68 A4 A5 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 58 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
armadillo (or containing that string) to compile C/C++ code or process data, where the binary or script header matches the YARA signature due to embedded metadata or specific byte patterns.
msbuild.exe, dotnet.exe, python.exe) or where the process path resides in standard development directories (e.g., C:\dev\, C:\builds\, C:\src\).ArmadilloAgent.exe, armadillo_scan.dll) for versioning or project codename purposes, triggering the rule on every host where the agent is installed.
ArmadilloAgent.exe or armadillo_scan.dll and the path is within the standard installation directory (e.g., C:\Program Files\InternalTools\Armadillo\).Armadillov220b1 in its scan set, causing the rule to match against the tool’s own configuration file, script, or embedded YARA database file during the scan process.
.yar, .yara, or .rules and are located in security tool directories (e.g., C:\Tools\YARA\, C:\Security\ThreatHunt\).