Contents
Campaign Identifier: Arsenal-237-New-Files-109.230.231.37
Last Updated: January 27, 2026
Threat Level: CRITICAL
Part of series: This is report 2 of 2 in the Arsenal-237 investigation. The original report, Arsenal-237: Threat Actor R&D Repository Exposed, documents the first 16 samples found in the same open directory (109.230.231.37) and is the recommended starting point; this follow-up analyzes the 11 samples added after that discovery.
Report Context: New Files from Arsenal-237 Directory
This report analyzes 11 new malware samples added to the same open directory (109.230.231.37) documented in early January 2026. These samples represent a significant capability jump from the original 16: the new additions introduce BYOVD kernel driver abuse, a kernel-mode rootkit, a CrowdStrike-specific EDR terminator, and enterprise-grade Rust ransomware, capabilities absent from the first wave.
BLUF: The Arsenal-237 Threat
Arsenal-237 is a modular ransomware toolkit built for enterprise compromise across three sequential phases: privilege escalation and defense disablement, persistence and credential access, then ransomware deployment.
In Phase 1 the operator escalates privilege and disables the defenses. lpe.exe reaches NT AUTHORITY\SYSTEM through five techniques, token impersonation from lsass.exe and winlogon.exe, registry UAC bypass via fodhelper.exe hijacking, and SYSTEM-level scheduled tasks. With SYSTEM privileges, killer.dll and its CrowdStrike-specific variant killer_crowdstrike.dll load the signed but vulnerable BdApiUtil64.sys (a Baidu antivirus driver) and issue kernel-mode IOCTL commands such as 0x800024B4 to terminate CSFalconService.exe, csagent.exe, and more than 20 other security products. rootkit.dll extends this by adding Unicode-based file hiding, API hooking for call interception, PowerShell integration, and anti-forensics measures that target process-monitoring and packet-analysis tools.
In Phase 2 they move to persistence and credential access. nethost.dll establishes persistence via DLL hijacking, beacons to hardcoded TCP targets (8.8.8.8:53 and 127.0.0.1:53), and supports PowerShell execution, system enumeration, and Base64-encoded exfiltration. chromelevator.exe uses reflective DLL injection and direct syscalls to extract cookies, passwords, and payment data from Chrome, Brave, and Edge credential stores.
In Phase 3 they deploy the ransomware. new_enc.exe targets Commvault agents (misidentified as Veritas Backup Exec at authoring and corrected 2026-09-13, once the referenced service short-names were confirmed against Commvault’s own published documentation) and VSS snapshots using a hardcoded ChaCha20 key (67e6096a…), a test-variant operational security lapse. full_test_enc.exe deploys multi-threaded hybrid encryption (RSA-OAEP plus ChaCha20) across all accessible drives and network shares without C2 dependence, which makes decryption impossible without the operator’s RSA private key. dec_fixed.exe, a victim-specific decryptor carrying a distinct hardcoded key (1e0d8597…), confirms per-victim key management and an active RaaS model (CONFIRMED).
The Organizational Threat in Plain Terms
When Arsenal-237 reaches a target environment, attackers gain the ability to:
- Disable security products using rootkit techniques (malware that hides at the deepest system level, defeating standard antivirus detection)
- Escalate privileges to SYSTEM level (gaining complete administrative control)
- Establish persistent backdoor access (maintaining control even after system reboots)
- Steal credentials from web browsers and credential stores
- Deploy ransomware that encrypts critical business data with hybrid cryptography (encryption so strong that even expert cryptographers cannot break it without the attacker’s private decryption key)
- Negotiate ransom demands with per-victim decryption capabilities as leverage
Evidence of active development (test builds recovered) indicates imminent deployment campaigns.
Executive Risk Summary
| Risk Factor | Score (1-10) | Business Impact |
|---|---|---|
| Overall Toolkit Risk | 9.5/10 | CRITICAL - Requires immediate attention from executive leadership |
| Data Encryption Risk | 10/10 | All enterprise data at risk; recovery requires external decryption keys |
| System Compromise | 9.5/10 | Complete infrastructure control possible; kernel-level persistence |
| Detection Evasion | 9/10 | Kernel rootkit defeats most detection systems; backup targeting |
| Operational Resilience | 9/10 | Distributed across multiple components; difficult to fully remediate |
| Ransomware Recovery | 8.5/10 | RSA-OAEP + ChaCha20 hybrid encryption; recovery without the operator’s private key is not possible |
Overall Risk Assessment: CRITICAL (9.5/10) - Executive escalation and immediate defensive action required.
Confidence Level Framework
- DEFINITE / CONFIRMED: Malware functionality directly observed in static/dynamic analysis
- HIGH (90%+): Multiple samples confirm behavior; attacks probable
- MODERATE (75-90%): Reasonable inference from code and attack patterns
- LOW (50-75%): Analytical judgment; requires additional evidence
Analysis Components: New Files
Arsenal-237 New Files: Recently Added Malware
Each sample has three companion resources: a technical report with behavioral analysis and response guidance, a detection package with YARA/Sigma rules, and a machine-readable IOC feed for SIEM/EDR ingestion.
| killer.dll (BYOVD Process Termination): | Technical Report | Detection Package | IOC Feed |
| killer_crowdstrike.dll (CrowdStrike Variant): | Technical Report | Detection Package | IOC Feed |
| lpe.exe (Privilege Escalation): | Technical Report | Detection Package | IOC Feed |
| BdApiUtil64.sys (Vulnerable Baidu Driver): | Technical Report | Detection Package | IOC Feed |
| rootkit.dll (Kernel-Mode Rootkit): | Technical Report | Detection Package | IOC Feed |
| nethost.dll (DLL Hijacking Persistence): | Technical Report | Detection Package | IOC Feed |
| chromelevator.exe (Browser Credential Theft): | Technical Report | Detection Package | IOC Feed |
| enc_c2.exe (Rust Ransomware with Tor C2): | Technical Report | Detection Package | IOC Feed |
| new_enc.exe (Human-Operated Ransomware): | Technical Report | Detection Package | IOC Feed |
| dec_fixed.exe (Ransomware Decryptor): | Technical Report | Detection Package | IOC Feed |
| full_test_enc.exe (Advanced Rust Ransomware): | Technical Report | Detection Package | IOC Feed |
Toolkit Component Overview
This landing page indexes 11 detailed analysis reports covering the complete Arsenal-237 attack chain. Each component report includes file hashes (MD5, SHA1, SHA256), IOC feeds, YARA/Sigma detection rules, behavioral analysis, and MITRE ATT&CK mappings.
Phase 1: Defense Evasion & Privilege Escalation (5 Components)
Five components disable security products and elevate attacker privileges to kernel level.
Phase 2: Persistence & Credential Access (2 Components)
Two components maintain access and harvest credentials from browsers.
Phase 3: Impact - Ransomware Deployment (4 Components)
Four components perform file encryption and provide victim-specific decryption capabilities.
Toolkit Architecture Overview
Design Philosophy: Professional Ransomware-as-a-Service
Arsenal-237 carries five markers of a mature Ransomware-as-a-Service (RaaS) operation:
- Modular architecture for flexible deployment
- Per-victim key management enabling affiliate tracking and decryption licensing
- Multiple evasion techniques targeting different security products
- Test/beta variants showing active pre-deployment iteration
- Rust implementation delivering cross-platform capability and memory safety
Toolkit Structure: Three Operational Phases
PHASE 1: Defense Evasion & Privilege Escalation
+-----------------------------------------------------+
| killer.dll / killer_crowdstrike.dll | Terminate security products
| lpe.exe | Escalate to SYSTEM
| BdApiUtil64.sys (vulnerable Baidu driver) | Acquire kernel access
| rootkit.dll | Hide malware from detection
+-----------------------------------------------------+
|
v
PHASE 2: Persistence & Credential Access
+-----------------------------------------------------+
| nethost.dll (masquerading .NET loader) | DLL hijacking persistence
| chromelevator.exe | Browser credential theft
+-----------------------------------------------------+
|
v
PHASE 3: Impact - Ransomware Deployment
+-----------------------------------------------------+
| enc_c2.exe / new_enc.exe / full_test_enc.exe | Encrypt critical data
| dec_fixed.exe | Victim-specific decryption
+-----------------------------------------------------+
Key Technical Characteristics
Cryptographic Foundation:
- RSA-OAEP + ChaCha20 hybrid encryption in advanced variants: decryption requires the operator’s RSA private key
- Per-victim key architecture enabling the RaaS affiliate model
- Hardcoded keys in test variants (67e6096a… in new_enc.exe; 1e0d8597… in dec_fixed.exe): operational security lapses that distinguish test builds from deployment variants
- Different keys across samples indicating builder/deployment tracking
Evasion Techniques:
- Kernel-mode rootkit hiding processes, threads, and drivers
- BYOVD kernel access via BdApiUtil64.sys
- CrowdStrike-specific variant (killer_crowdstrike.dll) indicating targeted EDR research
- Anti-VM and anti-analysis detection
Rust Implementation:
- Multi-threaded encryption via the Rayon library
- Memory safety that limits exploitation of the ransomware itself
- Cross-platform build capability
Component Analysis Index
All 11 components have individual detailed reports with full technical analysis, IOCs, and detection rules.
PHASE 1: DEFENSE EVASION & PRIVILEGE ESCALATION
1. killer.dll - Basic BYOVD Process Termination
This component is a security product disabler working through a vulnerable driver.
It is a driver-level process terminator that loads BdApiUtil64.sys for kernel access and terminates security product processes, and it serves as the foundation for the CrowdStrike-specific variant.
File Identifiers:
- MD5:
c031054f6140e2c366eaf4263f827dbf - SHA256:
10eb1fbb2be3a09eefb3d97112e42bb06cf029e6cac2a9fb891b8b89a25c788d
I hold this CONFIRMED, on static and behavioral analysis.
The full report is at ./killer-dll.md.
2. killer_crowdstrike.dll - CrowdStrike-Specific Process Termination
This component is an EDR-specific defense disabler.
It is a killer.dll variant with product-specific targeting of CSFalconService.exe and csagent.exe. The CrowdStrike-specific function names and driver interactions confirm the threat actor researched enterprise EDR deployments before building this variant.
File Identifiers:
- MD5:
6926ea1b4c4bff01a23b7e1728583348 - SHA256:
e26e9221f4e9a437716a28c08c5f74c6a2ecae2c47b77091db7d21f36ed2f7d3
I hold this CONFIRMED, on product-specific function names and driver interactions.
The full report is at ./killer_crowdstrike-dll.md.
3. lpe.exe - Privilege Escalation Wrapper
This component is a privilege escalation tool.
It is a privilege escalation wrapper using five techniques, token impersonation from lsass.exe and winlogon.exe, registry UAC bypass via fodhelper.exe hijacking, and SYSTEM-level scheduled tasks, to reach NT AUTHORITY\SYSTEM. Every kernel-mode operation in Phase 1 depends on the privileges this component delivers.
File Identifiers:
- MD5:
47400a6b7c84847db0513e6dbc04e469 - SHA256:
c4dda7b5c5f6eab49efc86091377ab08275aa951d956a5485665954830d1267e
I hold this CONFIRMED, on API calls and capability testing.
The full report is at ./lpe-exe.md.
4. BdApiUtil64.sys - Vulnerable Baidu Driver (BYOVD)
This component is a vulnerable driver used to reach kernel access.
It is a signed Baidu antivirus driver carrying a known privilege escalation vulnerability. Arsenal-237 loads it via BYOVD, abusing its legitimate Windows signature to pass kernel protection checks, then exploiting the vulnerability for kernel-mode code execution. This driver loading precedes rootkit injection.
File Identifiers:
- MD5:
ced47b89212f3260ebeb41682a4b95ec - SHA256:
47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
I hold this CONFIRMED, on a known CVE and its exploitation pattern.
The full report is at ./BdApiUtil64-sys.md.
5. rootkit.dll - Kernel-Mode Rootkit
This component is a kernel-mode rootkit providing persistence and hiding.
It is a kernel-mode rootkit installed via BYOVD exploitation. It hides malware processes, threads, and drivers from user-mode enumeration, maintains persistence across reboots, and adds Unicode-based file hiding, API hooking, PowerShell integration, and anti-forensics targeting process-monitoring and packet-analysis tools. User-mode detection tools cannot see the objects this rootkit conceals, so infected systems need kernel-mode forensics or a full rebuild.
File Identifiers:
- MD5:
674795d4d4ec09372904704633ea0d86 - SHA256:
e71240f26af1052172b5864cdddb78fcb990d7a96d53b7d22d19f5dfccdf9012
I hold this CONFIRMED, on kernel driver analysis.
The full report is at ./rootkit-dll.md.
PHASE 2: PERSISTENCE & CREDENTIAL ACCESS
6. nethost.dll - Masquerading .NET Loader (DLL Hijacking)
This component is a persistence mechanism working through DLL hijacking.
It masquerades as the legitimate .NET runtime component nethost.dll. Loaded by legitimate .NET processes, it establishes DLL-hijacking persistence that survives reboots, beacons to hardcoded TCP targets (8.8.8.8:53 and 127.0.0.1:53), and supports PowerShell execution, system enumeration, and Base64-encoded exfiltration.
File Identifiers:
- MD5:
f91ff1bb5699524524fff0e2587af040 - SHA256:
158f61b6d10ea2ce78769703a2ffbba9c08f0172e37013de960d9efe5e9fde14
I hold this CONFIRMED, on file analysis and the hijacking patterns.
The full report is at ./nethost-dll.md.
7. chromelevator.exe - Browser Credential Theft
This component is a credential harvesting tool.
It uses reflective DLL injection and direct syscalls to extract cookies, passwords, and payment data from Chrome, Edge, and Brave credential stores. The direct syscalls bypass EDR hooks that would normally flag credential-store access, and the stolen credentials enable lateral movement without further exploitation.
File Identifiers:
- MD5:
bc376c951eacb36bf0909a43588e6444 - SHA256:
92c4f4b7748f23d6dcd5af43595f34e4bb8e284a85d2c1647b189c1bb59a784a
I hold this CONFIRMED, on static analysis and behavioral observation.
The full report is at ./chromelevator-exe.md.
PHASE 3: IMPACT - RANSOMWARE DEPLOYMENT
8. enc_c2.exe - Rust Ransomware with Tor C2
This component is a ransomware encryptor, the remote-controlled variant.
It is Rust ransomware with real-time Tor-based C2 control and ChaCha20 file encryption. Builder ID tracking in the binary enables RaaS affiliate attribution. The Tor C2 channel lets the operator monitor encryption progress and coordinate ransom negotiation, and network-level blocking of the C2 IP is ineffective against Tor hidden services.
File Identifiers:
- MD5:
32a3497e57604e1037f1ff9993a8fdaa - SHA256:
613d4d0f1612686742889e834ebc9ebff6ae021cf81a4c50f66369195ca01899
I hold this CONFIRMED, on Rust code analysis and the C2 communication.
The full report is at ./enc_c2-exe.md.
9. new_enc.exe - Human-Operated Rust Ransomware (v0.5-beta)
This component is an advanced ransomware encryptor.
It is Rust ransomware (v0.5-beta) targeting Commvault agents and VSS snapshots with a hardcoded ChaCha20 key (67e6096a…). That hardcoded key is an operational security lapse, because files encrypted by this test variant are potentially decryptable without ransom payment. The v0.5-beta designation and the backup-targeting logic confirm a development iteration rather than a deployment-ready build, and operational deployments use enc_c2.exe or full_test_enc.exe instead.
File Identifiers:
- MD5:
a16ba61114fa5a40afce54459bbff21e - SHA256:
90d223b70448d68f7f48397df6a9e57de3a6b389d5d8dc0896be633ca95720f2
I hold this CONFIRMED, because binary analysis confirms both the hardcoded key and the targeting logic.
The full report is at ./new_enc-exe.md.
10. dec_fixed.exe - Ransomware Decryptor
This component is a victim-specific decryption tool.
It is a victim-specific decryptor carrying a key (1e0d8597…) distinct from every other Arsenal-237 sample, which is CONFIRMED evidence of per-victim key management. The per-victim key model is the operational signature of a RaaS platform, because it enables affiliate tracking, victim-specific negotiations, and decryption licensing control.
File Identifiers:
- MD5:
7c5493a0a5df52682a5c2ba433634601 - SHA256:
d73c4f127c5c0a7f9bf0f398e95dd55c7e8f6f6a5783c8cb314bd99c2d1c9802
I hold this CONFIRMED, on key analysis and decryption verification.
The full report is at ./dec_fixed-exe.md.
11. full_test_enc.exe - Advanced Rust Ransomware (RSA+ChaCha20)
This component is an enterprise-grade ransomware encryptor.
It is the most capable Arsenal-237 variant recovered. It deploys multi-threaded hybrid encryption (RSA-OAEP plus ChaCha20) across all accessible drives and network shares without C2 dependence. RSA-OAEP wraps each file’s ChaCha20 symmetric key with the operator’s public key, so only the operator’s RSA private key can recover it, and brute force is cryptographically infeasible. Recovery without that private key or unencrypted offline backups is not possible. The binary is 15.5 MB, carrying bundled cryptographic libraries.
File Identifiers:
- MD5:
1fe8b9a14f9f8435c5fb5156bcbc174e - SHA256:
4d1fe7b54a0ce9ce2082c167b662ec138b890e3f305e67bdc13a5e9a24708518
I hold this CONFIRMED, on cryptographic analysis and hybrid encryption verification.
The full report is at ./full_test_enc-exe.md.
Attack Chain Integration
How Components Work Together: A Complete Attack Scenario
Arsenal-237 executes in four sequential stages, each enabled by the previous.
STAGE 1: Initial Access (pre-toolkit) The attacker gains an initial foothold (phishing, RDP, supply chain) with user-level privileges.
STAGE 2: Defense Evasion
- lpe.exe escalates to NT AUTHORITY\SYSTEM
- BdApiUtil64.sys loads via the BYOVD technique, granting kernel-mode execution
- rootkit.dll hides malware processes, threads, and drivers from user-mode tools
- killer.dll or killer_crowdstrike.dll terminates security products via IOCTL 0x800024B4
STAGE 3: Persistence and Credential Access
- nethost.dll establishes DLL-hijacking persistence in legitimate .NET processes
- chromelevator.exe extracts cookies, passwords, and payment data from Chrome, Edge, and Brave
STAGE 4: Ransomware Deployment
- enc_c2.exe (Tor-based variant) or new_enc.exe / full_test_enc.exe begins file encryption
- Backups, databases, and documents across all accessible drives and network shares are encrypted
- dec_fixed.exe is issued to the victim only after ransom payment
Multi-Phase Attack Characteristics
| Phase | Objective | Components | Success Criteria |
|---|---|---|---|
| Phase 1 | Establish control, disable defenses | killer.dll, lpe.exe, BdApiUtil64.sys, rootkit.dll | Security products disabled, malware hidden |
| Phase 2 | Persist and gather intelligence | nethost.dll, chromelevator.exe | Credentials stolen, persistence established |
| Phase 3 | Execute impact and extort | enc_c2.exe, new_enc.exe, full_test_enc.exe, dec_fixed.exe | Data encrypted, ransom demand leverage |
Operational Maturity Indicators
Seven observed characteristics mark Arsenal-237 as a mature, professionally developed operation:
- Modular design: components deploy independently and compose into a full kill chain
- Product-specific variants: killer_crowdstrike.dll targets CSFalconService.exe and csagent.exe by name, confirming prior EDR research
- Hybrid cryptography: RSA-OAEP + ChaCha20 in full_test_enc.exe reflects expert cryptographic implementation
- Rust across the ransomware tier: a consistent modern language choice across enc_c2.exe, new_enc.exe, and full_test_enc.exe
- Per-victim key management: dec_fixed.exe carries a key (1e0d8597…) distinct from all encryptors, proving the RaaS model (CONFIRMED)
- Active beta iteration: v0.5-beta designation in new_enc.exe and “test” designation in full_test_enc.exe show iterative pre-deployment testing
- Hardcoded keys in test variants only: the operational security lapse in new_enc.exe is absent from enc_c2.exe and full_test_enc.exe, indicating intentional separation of test and deployment builds
MITRE ATT&CK Mapping
This landing page indexes eleven components, so its mapping is the union of theirs. Each row names the component that implements the technique, and the per-component reports carry the evidence behind it.
Confidence note: all rows below are HIGH confidence unless explicitly marked
(MODERATE). Tactics follow the current ATT&CK assignment, which places the EDR-termination capability under Defense Impairment rather than under the older Defense Evasion tree.
| Tactic / Technique | Name | Component |
|---|---|---|
| Execution / T1047 | Windows Management Instrumentation | lpe.exe |
| Execution / T1053.005 | Scheduled Task | lpe.exe, new_enc.exe |
| Execution / T1059 | Command and Scripting Interpreter | dec_fixed.exe |
| Execution / T1059.001 | PowerShell | rootkit.dll, nethost.dll |
| Execution / T1106 | Native API | chromelevator.exe |
| Execution / T1204.002 | Malicious File | enc_c2.exe |
| Persistence / T1543.003 | Windows Service | killer.dll |
| Persistence / T1547.001 | Registry Run Keys / Startup Folder | enc_c2.exe |
| Persistence / T1547.006 | Kernel Modules and Extensions | BdApiUtil64.sys |
| Privilege Escalation / T1068 | Exploitation for Privilege Escalation | killer.dll, killer_crowdstrike.dll, BdApiUtil64.sys, rootkit.dll |
| Privilege Escalation / T1548.002 | Bypass User Account Control | lpe.exe |
| Stealth / T1014 | Rootkit | BdApiUtil64.sys |
| Stealth / T1027 | Obfuscated Files or Information | killer.dll |
| Stealth / T1027.009 | Embedded Payloads | killer.dll |
| Stealth / T1055 | Process Injection | rootkit.dll |
| Stealth / T1055.001 | Dynamic-link Library Injection | rootkit.dll, chromelevator.exe |
| Stealth / T1070.004 | File Deletion | dec_fixed.exe |
| Stealth / T1134.001 | Token Impersonation/Theft | lpe.exe |
| Stealth / T1497.001 | System Checks | new_enc.exe |
| Stealth / T1564.001 | Hidden Files and Directories | rootkit.dll |
| Stealth / T1620 | Reflective Code Loading | chromelevator.exe |
| Stealth / T1622 | Debugger Evasion | enc_c2.exe, new_enc.exe |
| Defense Impairment / T1685 | Disable or Modify Tools | killer.dll, killer_crowdstrike.dll, BdApiUtil64.sys, rootkit.dll |
| Credential Access / T1555.003 | Credentials from Web Browsers | chromelevator.exe |
| Discovery / T1007 | System Service Discovery | nethost.dll |
| Discovery / T1057 | Process Discovery | new_enc.exe |
| Discovery / T1082 | System Information Discovery | nethost.dll |
| Discovery / T1083 | File and Directory Discovery | dec_fixed.exe |
| Discovery / T1135 | Network Share Discovery | full_test_enc.exe |
| Discovery / T1518.001 | Security Software Discovery | new_enc.exe |
| Command and Control / T1071.001 | Web Protocols | nethost.dll, enc_c2.exe |
| Command and Control / T1090 | Proxy | nethost.dll |
| Command and Control / T1090.003 | Multi-hop Proxy | enc_c2.exe |
| Command and Control / T1105 | Ingress Tool Transfer | nethost.dll |
| Exfiltration / T1020 | Automated Exfiltration | nethost.dll |
| Impact / T1486 | Data Encrypted for Impact | enc_c2.exe, dec_fixed.exe, full_test_enc.exe |
| Impact / T1489 | Service Stop | new_enc.exe |
| Impact / T1490 | Inhibit System Recovery | new_enc.exe |
That is 38 techniques across 10 tactics. The concentration in Stealth and Defense Impairment is the toolkit’s defining shape: five of the eleven components exist only to remove the defender’s visibility before the ransomware runs.
Threat Intelligence Summary
Arsenal-237 Attribution Context
The threat tier is a professional ransomware operation, likely a RaaS provider.
The operational model is Ransomware-as-a-Service, which I hold at HIGH confidence. The per-victim key architecture in dec_fixed.exe enables affiliate tracking, the builder ID in enc_c2.exe ties builds to affiliates, and the multiple scenario-specific variants support flexible affiliate deployment.
On geographic origin the evidence is INSUFFICIENT. Rust implementation and English-language strings are common globally and support no geographic attribution, and the Tor-based C2 in enc_c2.exe intentionally obscures the developer’s location.
On the threat activity timeline I sit at MODERATE, with active development underway. Multiple test and beta variants (new_enc.exe v0.5-beta, the full_test_enc.exe test version) confirm an active pre-deployment testing phase, and operational campaigns appear imminent or recently initiated.
Infrastructure Assessment
The C2 infrastructure is Tor-based, in enc_c2.exe, and CONFIRMED by observed beaconing. I hold at MODERATE confidence that multiple hidden service addresses provide redundancy, and this architecture defeats ISP-level and network-level blocking.
On the hosting model I sit at MODERATE. Infrastructure resilience indicators suggest abuse-tolerant hosting, consistent with standard RaaS operational practice.
Strategic Defensive Recommendations
For Executive Leadership
Arsenal-237 encrypts critical data with cryptography that cannot be broken, disables security products before encryption begins, persists through cleanup attempts, enables lateral movement, and provides ransom leverage through credible threat of permanent data loss.
Recommended Strategic Actions:
-
Treat this as a business continuity risk: Arsenal-237 is an operational attack platform, not a single malware variant. Response requires cross-functional coordination between security, legal, and business leadership.
-
Prioritize offline backup capability: if Arsenal-237 encrypts data, offline backups are the only recovery path that does not require ransom payment. Air-gapped or immutable-snapshot backup infrastructure must be isolated from production networks. Validate recovery procedures regularly.
-
Validate the incident response plan: IR plans should address ransomware-specific scenarios, define escalation authority, and include tabletop exercises that test decision-making under time pressure.
-
Review cyber insurance coverage: confirm coverage addresses ransomware response, forensic investigation, and extortion threats.
-
Prepare stakeholder communication plans: a successful Arsenal-237 deployment triggers breach-notification obligations under applicable data protection regulations. Coordinate legal, PR, and compliance postures before an incident, not during one.
For Security Leadership & CISOs
Defensive Priority Framework:
Priority 1: Detection and Prevention
- Behavioral EDR with kernel-mode visibility
- Network-level detection for Tor traffic
- Process injection monitoring (CreateRemoteThread, QueueUserAPC)
- Privileged process elevation monitoring (lpe.exe activity)
Priority 2: Threat Hunting (Assume Breach)
- Hunt for BYOVD exploitation attempts (BdApiUtil64.sys loading)
- Monitor for driver loading from non-system locations
- Hunt for security product termination behavior
- Detect DLL hijacking (nethost.dll outside expected system paths)
Priority 3: Isolation and Containment
- Network isolation of affected systems
- Credential rotation for compromised accounts
- C2 blocking at network perimeter
- Forensic evidence preservation before remediation
Priority 4: Recovery Readiness
- Validated offline backup and recovery procedures
- System rebuild runbooks pre-staged
- Critical data and system prioritization for recovery ordering
- Business continuity for critical functions identified in advance
For Security Operations Center (SOC) Teams
Individual component reports contain specific YARA signatures, Sigma rules, and hunting queries. Key detection areas:
-
BYOVD detection (Phase 1, components 3-4): monitor BdApiUtil64.sys loading; alert on kernel driver installation from non-system locations; track lpe.exe execution patterns
-
Security product termination (Phase 1, components 1-2): detect kernel-mode process termination targeting EDR/antivirus processes; flag IOCTL 0x800024B4 dispatch
-
Persistence indicators (Phase 2, components 6-7): detect nethost.dll in user-writable locations; monitor .NET processes loading unexpected DLLs; hunt for reflective DLL injection by chromelevator.exe
-
Ransomware behavior (Phase 3, components 8-11): alert on high-entropy bulk writes, file extension changes, and backup system read-ahead patterns; detect Tor traffic from non-Tor-user systems (enc_c2.exe C2)
Detection-to-response priorities:
- killer.dll / killer_crowdstrike.dll detected → isolate immediately; treat as Phase 1 chain in progress; begin forensic preservation
- lpe.exe or BYOVD activity detected → assume kernel-level access; standard user-mode tools are inadequate; plan for system rebuild rather than cleanup
- chromelevator.exe or credential-access indicators detected → credential rotation for affected accounts; expand hunt for lateral movement
- File encryption behavior detected → isolate immediately; preserve encrypted files for forensic analysis before any decryption attempt; identify offline backups
For Threat Hunting Teams
Hunt Scenarios:
-
BYOVD exploitation: BdApiUtil64.sys loading from non-system paths; kernel callback registrations from unsigned or low-reputation drivers (BdApiUtil64-sys.md)
-
Rootkit persistence: process and thread enumeration gaps indicating hidden objects; kernel API hooking anomalies; driver installation from unexpected locations (rootkit-dll.md)
-
DLL hijacking: nethost.dll present outside system directories; .NET processes loading DLLs from user-writable paths; anomalous DLL version signatures (nethost-dll.md)
-
Browser credential theft: reflective DLL injection into browser processes; SQLite reads of Chrome/Edge credential stores via direct syscalls (chromelevator-exe.md)
-
Ransomware encryption: bulk file access with high-entropy writes; file extension changes; backup system enumeration patterns (Phase 3 component reports)
FAQ - Addressing Common Questions
Technical Questions
Q1: “How is Arsenal-237 different from other ransomware families?”
Arsenal-237 is a complete operational attack platform, not a ransomware-only tool. Most ransomware families focus on encryption. Arsenal-237 adds a kernel-mode rootkit (rootkit.dll) that operates below standard security tools, hiding malware from user-mode detection and making cleanup inadequate, affected systems require a full rebuild rather than a scan-and-remove approach.
The operational sequence distinguishes Arsenal-237 further: security products are terminated before encryption begins, persistence survives reboots via DLL hijacking, and credentials are stolen for lateral movement before the ransomware stage. This makes it an end-to-end compromise platform rather than a standalone encryptor.
Q2: “Can we decrypt files encrypted with full_test_enc.exe?”
No. full_test_enc.exe uses RSA-OAEP + ChaCha20 hybrid encryption: each file’s ChaCha20 symmetric key is wrapped with the operator’s RSA public key. Decryption requires the operator’s RSA private key, which only the attacker holds. Brute-force is cryptographically infeasible (2^256 key space). External decryption services cannot help.
Recovery paths without the private key: offline backups, or law enforcement obtaining the key (uncommon). Ransom payment in exchange for dec_fixed.exe is the only other route.
Q3: “Does the hardcoded key in new_enc.exe mean we can decrypt those files?”
Possibly, but only if the attack used new_enc.exe specifically. The hardcoded ChaCha20 key (67e6096a…) is a test-variant operational security lapse: files encrypted by this build may be decryptable without ransom payment.
Important caveats: new_enc.exe is a v0.5-beta development build. Operational deployments likely use enc_c2.exe or full_test_enc.exe, which do not have hardcoded keys. Forensic analysis of encrypted files can confirm which variant was used, early-stage testing may have involved the beta build, but later deployments almost certainly did not.
Q4: “What is RaaS (Ransomware-as-a-Service) and why does it matter?”
RaaS is a criminal services model: a core developer builds and maintains the ransomware platform; affiliates access it to conduct attacks; the core developer takes a share of each ransom payment. Each victim receives unique encryption keys tied to that affiliate’s deployment.
Arsenal-237’s RaaS evidence: per-victim key architecture in dec_fixed.exe (key 1e0d8597… differs from all encryptors), and builder ID tracking in enc_c2.exe enabling per-affiliate attribution.
For defenders, RaaS means: multiple affiliates with varied targeting patterns; per-victim keys ensuring ransom payment is the only decryption path outside offline recovery; and sustainable revenue driving continuous platform development.
Q5: “The reports mention ‘test builds’. Does this mean the threat isn’t real yet?”
No. Test builds indicate active development and imminent or recent operational deployment, not that the threat is theoretical. The v0.5-beta designation on new_enc.exe and “test version” on full_test_enc.exe confirm the toolkit is under active iteration. Multiple variants under simultaneous development suggest an operational timeline measured in weeks to months, not years. The threat is active (MODERATE confidence).
Operational Questions
Q6: “What should we do immediately if we detect Arsenal-237?”
Immediate priorities on any Arsenal-237 detection: network isolation of affected systems, credential rotation for affected accounts, forensic preservation before remediation, and threat hunting across the environment for lateral movement indicators. Assume the worst-case phase (ransomware deployed) until investigation rules it out. See individual component reports for component-specific detection guidance and the Incident Response Procedures section below for the response priority framework.
Q7: “Should we rebuild systems or attempt cleanup if Arsenal-237 is detected?”
Rebuild. rootkit.dll operates at the kernel level and hides itself from user-mode tools, cleanup cannot verify the rootkit was fully removed. Standard scan-and-remove approaches are inadequate for kernel-mode malware. A system rebuild from clean media is the only reliable remediation path for any system where Phase 1 components (rootkit.dll, BYOVD exploitation) are confirmed.
Q8: “How long will it take to recover from an Arsenal-237 attack?”
Recovery time depends on backup strategy and ransomware variant. With validated offline backups, recovery follows a rebuild-then-restore sequence whose duration scales with environment size and data volume. Without offline backups, options reduce to ransom payment for the decryption key or data loss. The offline backup strategy is the single largest determinant of recovery speed and outcome.
Q9: “What is ‘offline backup’ and how do we implement it?”
Offline backup means storage that is not accessible from the production network and therefore cannot be encrypted by ransomware. Arsenal-237’s new_enc.exe specifically targets Commvault agents and VSS snapshots, confirming that network-connected backup infrastructure is within the attack scope.
Two categories of offline backup offer protection:
-
Air-gapped storage: backup writes to external media that is physically disconnected after each job. Ransomware cannot reach storage that has no network path to it.
-
Immutable cloud snapshots: cloud-provider snapshot policies that prevent modification or deletion after creation. Requires proper permission segregation so ransomware cannot reach backup management APIs.
Both strategies require periodic recovery testing to confirm the backups are actually usable. An untested backup strategy is not a recovery strategy.
Q10: “Can we detect Arsenal-237 before the ransomware phase?”
Yes, detection opportunities exist at every phase. Phase 1 offers the best window: BYOVD exploitation, kernel driver loading from non-system paths, privilege escalation activity, and security product termination are all observable with kernel-mode EDR visibility. Phase 2 offers DLL hijacking indicators and credential store access patterns. Phase 3, file encryption and Tor C2 traffic, is the last opportunity before data loss.
Detection before Phase 3 depends on behavioral EDR with kernel-mode visibility, active threat hunting, and network monitoring for Tor traffic. Mature detection programs will identify Arsenal-237 at Phase 1 or Phase 2 (HIGH confidence).
Business/Risk Questions
Q11: “What is the business risk if we’re attacked with Arsenal-237?”
A successful Arsenal-237 deployment affects organizations across four impact dimensions:
- Ransom payment risk: per-victim key architecture means ransom is the only decryption path without offline backups; the negotiated amount scales with organizational size and sector
- Incident response burden: forensic investigation, legal/compliance consultation, and breach notification require specialized resources and extended timelines
- Operational disruption: recovery from a full-kit deployment requires system rebuilds across affected infrastructure, with downtime duration proportional to environment size and backup posture
- Regulatory and reputational consequences: a successful deployment triggers breach-notification obligations under applicable data protection frameworks; contractual and regulatory consequences follow from confirmed data exposure
The offline backup strategy is the largest single variable in business impact: organizations with validated offline backups can rebuild and restore; those without face the ransom payment decision.
Key Takeaways
1. Arsenal-237 is an operational attack platform, not a standalone encryptor. It coordinates privilege escalation, kernel-mode defense disablement, persistence, credential theft, and ransomware across 11 components. Standard single-layer remediation and signature-based detection are insufficient against a toolkit built to disable those defenses before impact begins.
2. Offline backups are the only reliable recovery path. full_test_enc.exe’s RSA-OAEP + ChaCha20 hybrid encryption cannot be broken without the operator’s private key. No external decryption service can help. Without validated offline backups, affected organizations face the ransom payment decision, with no third alternative. Backup strategy is the dominant variable in recovery outcome.
3. Detection at Phase 1 or Phase 2 prevents encryption. Arsenal-237 exposes observable indicators at every phase. BYOVD exploitation, kernel driver loading, security product termination, and DLL hijacking are all detectable with behavioral EDR and kernel-mode visibility, hours to days before the ransomware stage. Detection programs that catch Phase 1 or Phase 2 activity avoid the data loss scenario entirely.
4. Targeted industries face elevated risk. Enterprise backup targeting (new_enc.exe hitting Commvault and VSS), a CrowdStrike-specific EDR terminator, and per-victim key management all indicate Arsenal-237 is designed for environments where ransomware disruption translates to maximum leverage: healthcare, financial services, manufacturing, and large enterprises. Organizations in these sectors should prioritize Arsenal-237 in their threat models.
5. Technical compensating controls are non-negotiable. BYOVD techniques abuse legitimately signed drivers that bypass signature-based detection. chromelevator.exe uses direct syscalls to defeat EDR hooks. rootkit.dll hides from user-mode tools entirely. User training addresses only one attack vector. Defense-in-depth (behavioral EDR, kernel-mode visibility, threat hunting, and network monitoring) is the required baseline against this toolkit.
Confidence Levels Summary
Findings Organized by Confidence Level
CONFIRMED / DEFINITE (Direct observation)
- Arsenal-237 toolkit contains 11 distinct malware components
- BYOVD exploitation using BdApiUtil64.sys confirmed
- rootkit.dll hides processes, threads, and drivers at the kernel level
- full_test_enc.exe uses RSA-OAEP + ChaCha20 hybrid encryption: decryption without the operator’s private key is not possible
- new_enc.exe contains a hardcoded ChaCha20 key (67e6096a…): a test-variant operational security lapse
- dec_fixed.exe carries a distinct key (1e0d8597…) confirming per-victim key management
- enc_c2.exe beacons to Tor C2 infrastructure
- Rust implementation across enc_c2.exe, new_enc.exe, and full_test_enc.exe
- killer.dll and killer_crowdstrike.dll terminate security products via kernel-mode IOCTL
- nethost.dll establishes persistence via DLL hijacking
HIGH confidence (Strong corroborating evidence)
- Arsenal-237 operates as a RaaS platform: per-victim key architecture and builder ID tracking in enc_c2.exe both support this
- Active development underway: v0.5-beta and test-version designations confirm a pre-deployment iteration cycle
- killer_crowdstrike.dll’s product-specific targeting of CSFalconService.exe and csagent.exe indicates prior EDR research
MODERATE confidence (Reasonable inference)
- Multiple affiliates deploying the platform in decentralized campaigns
- Enterprise organizations are primary targets: backup targeting in new_enc.exe and CrowdStrike-specific disabler both align with high-value enterprise environments
- Tor infrastructure suggests sustained operations, not a single campaign
- Operational deployment timeline: weeks to months from report date
LOW confidence (Analytical judgment, insufficient evidence)
- Attribution to a specific named threat actor group: INSUFFICIENT evidence across this sample set
- Development team size estimation: not determinable from current evidence
Incident Response Procedures
If Arsenal-237 Has Been Detected (CONFIRMED Infection)
Immediate actions (any component detected):
- Network isolation of affected systems before any other action
- Credential rotation for accounts on affected systems
- Forensic preservation: do not reboot; begin memory and disk imaging
- Block identified C2 infrastructure at network perimeter
- Activate incident response procedures
Investigation priorities:
- Determine which Arsenal-237 phase is present (Phase 1, 2, or 3)
- Scope lateral movement: search for other systems with the same attack patterns or affected user accounts
- If Phase 3 detected: do not attempt decryption; preserve encrypted files for forensic analysis
- Hunt for Phase 1 and Phase 2 indicators across the environment in parallel
Containment:
- Isolate affected systems and disable compromised accounts
- Hunt for BYOVD indicators, kernel driver loading from non-system paths, DLL hijacking in .NET processes, and Tor traffic
- Forensic imaging of affected systems before remediation begins
Remediation decision:
- Any system where Phase 1 components (rootkit.dll, BYOVD) are confirmed requires a full system rebuild. Cleanup is not reliable for kernel-mode malware.
- If Phase 3 is active: isolate backup systems immediately to prevent encryption spread; initiate restoration from offline backups.
| Factor | Rebuild | Cleanup |
|---|---|---|
| Kernel-mode rootkit confirmed | Mandatory | Inadequate, rootkit hides itself from cleanup tools |
| Phase 3 ransomware detected | Preferred | Higher risk; only if no rootkit confirmed |
| Offline backups available | Rebuild + restore | Parallel option |
| No backups available | Still recommended | Only option outside ransom payment |
Related Resources & Further Reading
Individual Component Reports
Access detailed technical analysis for each toolkit component:
- Phase 1 - Defense Evasion Components:
- Phase 2 - Persistence & Credential Access Components:
- Phase 3 - Ransomware Components:
Detection & Hunting Resources
- IOC Feeds: See individual component reports for file hashes, C2 infrastructure, and behavioral indicators
- YARA Rules: See individual component reports for malware detection signatures
- Hunting Queries: See individual component reports for SIEM/EDR hunting procedures
- Network Signatures: See individual component reports for Suricata/Snort rules
External References
-
MITRE ATT&CK: the full technique mapping for this toolkit is in the MITRE ATT&CK Mapping section above, and each component report carries the evidence for its own rows.
-
Ransomware-as-a-Service Research:
- Provides context for Arsenal-237’s operational model
- Documents typical RaaS platform architecture and affiliate structures
License
© 2026 Joseph, The Hunters Ledger. Licensed under CC BY 4.0, free to republish and adapt, including commercially, with attribution to The Hunters Ledger and a link to the original.