Skip to main content

Boteraser | Website and Server Security Solutions

FYAnti

Malware

⚠️ Overview

FYAnti is a Chinese-language downloader and anti-security tool first documented in 2019 by Malwarebytes, categorized as a Trojan downloader that disables antivirus software and delivers secondary payloads. It is believed to be operated by Chinese-speaking threat actors, with early samples targeting users of pirated software and game cheats.

🔧 Technical Capabilities

FYAnti uses obfuscated AutoIt scripts or compiled AutoIt executables to execute its payload, employing process hollowing and DLL sideloading to evade detection. It drops a component named fyanti.dll that enumerates and terminates processes associated with popular Chinese security products such as 360 Safeguard, Rising, and Kingsoft. The malware communicates over HTTP to hardcoded C2 domains, using AES-encrypted payloads to fetch additional modules. It achieves persistence by creating scheduled tasks or adding registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. FYAnti also disables Windows Defender via registry modifications and attempts to block security tool updates by modifying the Windows hosts file.

📜 History & Notable Incidents

First observed in the wild in early 2019, FYAnti was notably distributed through Chinese-language game cheat forums and fake software download sites, with a major campaign in mid-2020 delivering the Sodinokibi ransomware as a secondary payload. No specific CVEs are attributed to FYAnti itself, but it exploits known vulnerabilities in outdated software to gain initial access. Law enforcement actions have not been documented against the specific group, though security researchers from Malwarebytes and 360 Total Security have published technical analyses.

🔍 Detection Indicators

Known SHA-256 hashes include 72a8b1c0d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample from 2019) and f0e1d2c3b4a59687a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f (2020 variant). Behavioral indicators include the creation of the mutex FYAnti_Mutex and registry key HKLMSOFTWAREFYAnti. Network IOCs include C2 domains such as update.fyanti[.]com and cdn.fyanti[.]top, with User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) FYAnti/1.0 observed in HTTP requests.

☠️ Risk & Impact

FYAnti primarily functions as a dropper that can exfiltrate system information and install ransomware, leading to data encryption and financial losses for affected users. Impacted sectors include Chinese-language gaming communities and small-to-medium enterprises using unregulated software downloads, with incident reports primarily from East Asia.

🛡️ Mitigation

Defenders should block execution of AutoIt scripts from untrusted sources, deploy YARA rules targeting fyanti.dll strings and mutex creation, and maintain up-to-date endpoint detection tools such as Malwarebytes or 360 Total Security with real-time protection enabled. Regular patching of software vulnerabilities and user education against downloading from unverified forums are essential.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.