Soul is a modular Windows espionage malware framework active since at least 2017 and used in cyber-espionage operations targeting government and other strategic sectors in Southeast Asia, including defense, healthcare, and information and communications technology. It has been linked in multiple investigations to Chinese-aligned intrusion activity, including operations associated with the Sharp Panda/Sharp Dragon cluster, although public attribution to a single actor is not definitive.
The framework evolved from an early backdoor that incorporated code derived from Gh0st RAT, NetBot, HTran, DynamiCall, and 7zip-related components into a more mature multi-stage platform centered on the SoulSearcher loader and multiple in-memory modules. Later variants emphasized stealth by storing compressed payloads and configuration data in the Windows registry and reflectively loading modules directly into memory rather than writing them to disk. SoulSearcher variants have used binary, XML, and semicolon-delimited configurations, validated and decompressed embedded or registry-resident payloads, and loaded one or more Soul modules through exported entry points.
Soul provides backdoor and post-compromise functionality through modular components. Observed capabilities include victim fingerprinting, command-and-control over custom HTTP traffic, registry-based persistence and storage, file and shell-related tasking in earlier backdoor generations, proxy functionality, and staged loading of additional command DLLs. Associated modules and configurations indicate support for keylogging, clipboard capture, file monitoring, service installation, and auxiliary collection features. Dedicated keylogger components compiled across multiple years captured keystrokes and clipboard data, including input methods relevant to some Asian-language environments.
Operationally, Soul has appeared in spearphishing-led intrusion chains in which weaponized documents and intermediate downloaders delivered SoulSearcher, which then decrypted and loaded the Soul framework in memory. Newer backdoor variants appear more specialized as orchestration layers for loading follow-on modules rather than directly exposing the full range of operator commands. Across components, recurring traits include import obfuscation, stack strings, shared compression and encryption routines, and closely related development patterns, indicating a maintained malware ecosystem built for long-term espionage and covert post-exploitation on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the Soul framework... Sharp Dragon has transitioned from using VictoryDll and the SoulSearcher framework to adopting Cobalt Strike Beacon
the Soul framework... Sharp Dragon has transitioned from using VictoryDll and the SoulSearcher framework to adopting Cobalt Strike Beacon
23 distinct techniques documented for this family, organized by ATT&CK tactic.
0x23000000 It opens an interactive CMD shell, allowing the attacker to execute CMD commands until terminating the shell by sending the “Exit” command.
The module is stored as a compressed blob with a custom header in the registry. It is never written to disk.
Appendix A: MITRE ATT&CK Techniques ID Description T1055 Process Injection
The configuration contains... <SelfDestroy>2029-07-11 15:29:32</SelfDestroy>
The dropper LZMA-decompresses the backdoor and a configuration that they both share.
Computer name and information about the current user, such as admin rights retrieved with NetUserGetInfo API
Every request to the server is composed of hardcoded HTTP headers impersonating legitimate network traffic to taboola[.]com.
Proxy These samples’ configuration indicates proxy capabilities over HTTP and HTTPS, as well as the ability to run CMD commands.
When one of the five named commands is received, the backdoor downloads and executes a DLL from the server.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously used malware framework/backdoor in Sharp Dragon operations that was later replaced by Cobalt Strike Beacon in observed campaigns.
A modular espionage malware framework used in Southeast Asian intrusions. SoulSearcher acts as a second-stage loader that decrypts, decompresses, and reflectively loads the Soul main module from memory. The Soul backdoor communicates over HTTP with a custom C2 protocol, fingerprints victims, supports configurable 'radio silence' hours, stores modules in the registry, and primarily loads additional in-memory modules for follow-on activity.
A modular Windows malware framework used in espionage operations. It evolved from an earlier backdoor into reflectively loaded in-memory modules that collect sensitive information, execute commands, manipulate files, open interactive shells, proxy traffic, and load additional malicious DLL modules from the registry or from the C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.