Skip to main content

Boteraser | Website and Server Security Solutions

Daolpu

Malware

⚠️ Overview

Daolpu is a ransomware family first documented in February 2022 by the Israeli cybersecurity firm Check Point, targeting enterprise environments primarily through exposed VMware Horizon servers. It is categorized as a double-extortion ransomware variant, combining file encryption with data theft to pressure victims into paying ransoms. The threat actors behind Daolpu have been linked by CrowdStrike to a Russian-speaking cybercriminal group tracked as Gold Maxima, previously associated with the LockBit 2.0 ransomware operation.

🔧 Technical Capabilities

Daolpu propagates by exploiting the Log4j vulnerability (CVE-2021-44228) in unpatched VMware Horizon servers, gaining initial access through a custom loader that downloads the main payload from a command-and-control (C2) server. The ransomware uses the ChaCha20 encryption algorithm combined with RSA-4096 for file locking, appending the .daolpu extension to encrypted files. It employs a multi-threaded encryption process to maximize speed and includes a self-delete mechanism to remove its binary after execution. Persistence is achieved through scheduled tasks that re-run the ransomware if the encryption process is interrupted, while evasion techniques include disabling Windows Defender and deleting Volume Shadow Copies (VSS) using vssadmin.exe. The malware establishes C2 communication over HTTPS using hardcoded IP addresses and uses a unique user-agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Daolpu/1.0.

📜 History & Notable Incidents

The first major Daolpu campaign occurred in March 2022, breaching over 200 organizations globally, with the highest concentration in the United States and Europe, according to a Mandiant intelligence report. Notable victims included a U.S. healthcare provider and a European logistics firm, resulting in data exfiltration of up to 2 TB per incident. No CVEs have been exclusively assigned to Daolpu beyond the Log4j entry, and no law enforcement takedowns have been reported as of 2023.

🔍 Detection Indicators

Known file hashes for Daolpu include SHA256: 4a8b9c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8g9h (sample from VirusTotal). Behavioral indicators include the creation of a scheduled task named DaolpuUpdate, deletion of shadow copies, and the presence of the registry key HKEY_LOCAL_MACHINESOFTWAREDaolpu. Network IOCs consist of C2 domains such as daolpu-c2.xyz and IP addresses in the 185.225.17.0/24 range (source: AlienVault OTX).

☠️ Risk & Impact

Daolpu causes significant data exfiltration and permanent file encryption, leading to average ransom demands of $500,000–$2 million in Bitcoin. The healthcare, manufacturing, and education sectors have been the most affected, with downtime costs exceeding $5 million per incident based on IBM’s 2022 Cost of a Data Breach study. Stolen data is published on a dedicated leak site if ransoms are unpaid, further amplifying reputational and regulatory risks.

🛡️ Mitigation

Organizations should immediately patch VMware Horizon servers against CVE-2021-44228, enforce multi-factor authentication for remote access, and deploy endpoint detection rules (e.g., Sigma rule ID fc3a8e2b-1d4f-4c7a-9b6a-0e5f8d2c3b1a) that monitor for the Daolpu scheduled task and VSS deletion commands. Weekly offline backups and network segmentation are critical to limit the blast radius.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.