Waterbear, also known as DBGPRINT, is a long-running Windows backdoor associated with the China-linked espionage cluster commonly tracked as BlackTech and also linked to HUAPI/Plead. Active since at least 2009, it has been used as a second-stage implant in intrusions targeting organizations in East Asia, including Taiwanese government environments, and has also been observed against government, education, healthcare, finance, technology, and think tank sectors.
Waterbear is notable for its modular and comparatively sophisticated design. Campaigns have used a multi-component architecture that commonly includes a PE loader, a DLL containing injected shellcode, and a final malicious payload. The malware evolved across numerous versions over roughly a decade, adopting shellcode-based staging, in-memory implant decryption and execution, plugin loading, and later tradecraft such as double DLL sideloading and x64 support. Its staging logic includes anti-analysis measures such as debug checks and self-modifying or pattern-elimination techniques intended to hinder detection.
The malware establishes execution by using a stager that initializes APIs dynamically, checks network conditions including proxy settings, derives session material, validates the remote server through a challenge mechanism, decrypts the implant, and runs it directly in memory. Reported variants use encrypted communications and custom key derivation, including RC4-based routines in the staging workflow.
Waterbear provides broad post-compromise functionality typical of an espionage backdoor. Documented capabilities include drive and file enumeration, file upload and download, file execution and manipulation, window enumeration and control, screenshot capture, remote desktop functions, process and service management, network connection management, remote shell access, and registry management. It has also been described as incorporating anti-antivirus functionality. In observed operations it served as a persistent foothold and flexible second-stage platform for follow-on activity and data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
dbgPrint 為中國駭客族群 HUAPI 慣用的後門程式,其名稱來自於該後門程式早期版本的字串(strings)內容。dbgPrint 後門程式通常由 PE 型態的 Loader、插入 shellcode 的 DLL 檔及惡意 Payload 所組成。
Malware Profile: DBGPRINT — Alias Waterbear; Since at least 2009; DLL export name “DbgPrint”; Acted as second stage; Advanced malware design; Adopt shellcode stager; Able to load the plugins.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
RC4 Key of Payload XOR / Shift Random 16 bytes File path String + File name
Actor Injects RC4 Decryption svchost.exe SecurityProduct Injects Injects
RC4_KSA(Pre-session key) decrypted data size header = RC4_PRGA(PRGA_data1) decrypted data size = Modified_RC4_PRGA(PRGA_data2) decrypted data header = Modified_RC4_PRGA(PRGA_data3) decrypted data = Modified_RC4_PRGA(PRGA_data4)
(White) Benign EXE (Gray) Malicious DLL (Black) Malicious DLL
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor/RAT associated in the content with the HUAPI/Plead/Blacktech cluster. It is described as being composed of a PE loader, a DLL containing shellcode, and a malicious payload, and also having anti-antivirus functionality.
Mentioned as another malware family in the Earth Hundun ecosystem.
A modular backdoor/implant used as a second-stage payload. It uses a shellcode stager, decrypts and executes implants in memory, supports plugin loading, and provides capabilities including file management, screenshot capture, remote desktop, process/network/service management, remote shell, and registry manipulation. The presentation also describes anti-debugging, proxy checks, session-key/challenge-based communications, RC4-based decryption, self-modifying code, and double DLL sideloading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.