logo

ThreatLabz

ID: 62705a7c-e5ee-5454-83bb-11546249bf84

STIX ID: report--62705a7c-e5ee-5454-83bb-11546249bf84

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This technical analysis details APT41’s use of a signed-executable DLL sideloading chain: the DodgeBox reflective loader (sbiedll.dll) decrypts an AES-CFB-configured payload (sbiedll.dat) and loads the MoonWalk backdoor, which uses Google Drive for C2. The report examines DodgeBox’s features including salted FNV1a API resolution, DLL unhooking, Control Flow Guard bypassing, machine-targeted payload keying, DLL hollowing/reflective loading, execution guardrails (argument, MAC/computer name, privilege checks), and call-stack spoofing used to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.