Skip to content

Malware

Chrysalis

According to Rapid7, Chrysalis is a custom, feature-rich backdoor.

Chrysalis is a Windows malware family operated by LOTUS PANDA.

Background

Rapid7 describes Chrysalis as a bespoke, capability-rich backdoor. Its broad feature set points to a polished, long-lived tool rather than a disposable utility. It abuses legitimate binaries to sideload a purpose-built DLL given a generic name, undermining detection that relies on filenames alone. Both the loader and the main module employ custom API hashing, each with its own resolution scheme, alongside layered obfuscation and a reasonably organized model for C2 communication.


Source: Malpedia (Fraunhofer FKIE).