APT 41 Attacks

Overview

This report outlines activity by APT41, including newly identified malicious samples, accompanying YARA rules for detection, and practical TI lookup queries to identify related threats. These findings provide actionable insights for detecting and mitigating APT41’s evolving tactics. It is not an in-depth analysis of APT41’s tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.

About APT 41

APT41 is a Chinese state-sponsored cyber espionage group with dual motives: conducting cyber espionage and financially motivated cybercrime. The group primarily targets sectors such as telecommunications, healthcare, manufacturing, and transportation. Geographically, its operations span Asia, Europe, and the Middle East, with notable activity in countries like Germany, Italy, and the United Kingdom. APT41 is known for its advanced techniques and tools, focusing on intellectual property theft, surveillance, and establishing strategic access to targeted systems.

Origin Country

China

Motivation

Espionage

Financial gain

First Seen

2012

Targeted Countries

  • United States of America
  • United Kingdom
  • Turkey
  • Thailand
  • Taiwan
  • Spain
  • Italy
  • United Arab Emirate
  • Qatar
  • Philippines
  • India
  • Germany
  • France
  • Fiji

Industries Attacked

  • Transport
  • Telecommunications
  • Technologies
  • Road transport
  • Medias and audiovisual
  • Manufacturing
  • Logistics
  • Insurance services
  • Hospitality
  • Heavy industries
  • Universities
  • Healthcare services
  • Government and administrations
  • Gambling
  • Finance
  • Entertainment industry
  • Energy
  • Air transport

DUSTTRAP

  • Rising from the Dust

  • Updated arsenal of APT41

  • Earth Baku Latest Campaign

  • SHA-256: c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db

  • Sample: ANY.RUN

  • SHA-256: 33fd050760e251ab932e5ca4311b494ef72cee157b20537ce773420845302e49

  • Sample: ANY.RUN

  • SHA-256: 22a50cea6ad67a7e8582d2cd4cdc3eaaf57c0fbe8cd062a9b15710166e255a86

  • Sample: ANY.RUN

HELLOBOT

  • Melofee: Unveiling a New Linux Threat

  • SHA-256: 2e62d6c47c00458da9338c990b095594eceb3994bf96812c329f8326041208e8

  • Sample: ANY.RUN

  • SHA-256: 407ab8618fed74fdb5fd374f3ed4a2fd9e8ea85631be2787e2ad17200f0462b8

  • Sample: ANY.RUN

  • SHA-256: 187b6a4c6bc379c183657d8eafc225da53ab8f78ac192704b713cc202cf89a17

  • Sample: ANY.RUN

  • SHA-256: 2801a3cc5aed8ecb391a9638a3c6f8db58ca3002e66f11bf88f8c7c2e5a6b009

  • Sample: ANY.RUN

SPHIJACKER

  • Earth Longzhi Returns with New Tricks

  • SHA-256: 7910478d53ab5721208647709ef81f503ce123375914cd504b9524577057f0ec

  • Sample: ANY.RUN

ShadowPad

  • APT41 compromised Taiwanese government-affiliated research institute

  • SHA-256: 2e46fcadacfe9e2a63cfc18d95d5870de8b3414462bf14ba9e7c517678f235c9

  • Sample: ANY.RUN

DUSTPAN

  • Rising from the Dust

  • SHA-256: c3efcb6efad675613721910a783389a646b2d138c7721df9849b28952d25bcfc

  • Sample: ANY.RUN

(Powershell Backdoor from APT 41)

  • Powershell Backdoor with Telegram C2

Before execution, the PowerShell backdoor creates a mutex named “v653Bmua-53JCY7Vq-tgSAaiwC-SSq3D4b6. Malware commonly uses mutexes to avoid multiple infections of the same system.

The PowerShell backdoor adds its payload to the HKCU\Environment\UserInitMprLogonScript registry key to establish persistence and uses forfiles.exe to execute its commands. This ensures that the malicious payload runs automatically every time the user logs into the system.

With the following TI lookup queries, we can search through public tasks and identify these malicious activities.

TI lookup: syncObjectName:"v653Bmua-53JCY7Vq-tgSAaiwC-SSq3D4b6"

TI lookup: registryKey:"HKEY_CURRENT_USER\\ENVIRONMENT" AND registryValue:"*forfiles.exe*"


  • SHA-256: bb3d35cba3434f053280fc2887a7e6be703505385e184da4960e8db533cf4428
  • Sample: ANY.RUN

VOLDEMORT

  • Espionage Campaign with Voldemort

  • SHA-256: fa383eac2bf9ad3ef889e6118a28aa57a8a8e6b5224ecdf78dcffc5225ee4e1f

  • Sample: ANY.RUN

MELOFEE

  • Melofee: Unveiling a New Linux Threat

Melofee attempts to establish persistence by writing a command to execute itself into the system files /etc/rc.local or /etc/rc.d/rc.local when running with root privileges, ensuring automatic execution during system boot. If running as a regular user, it adds the command to .bash_profile, .bash_login, or .profile to achieve auto-execution upon user login. [T1037.004]

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: MITRE:"T1037.004" and filePath:"/etc/rc.local"


  • SHA-256: a5a4284f87fd475b9474626040d289ffabba1066fae6c37bd7de9dabaf65e87a

  • Sample: ANY.RUN

  • SHA-256: 2db4adf44b446cdd1989cbc139e67c068716fb76a460654791eef7a959627009

  • Sample: ANY.RUN

PINEGROVE

  • Rising from the Dust

  • SHA-256: c40db0438a906eb0bec55093f1a0f2cc4cdc38104af0b4b4b3f18200a635c443

  • Sample: ANY.RUN

SQLULDR2

  • Rising from the Dust

Mimikatz

  • APT41 compromised Taiwanese government-affiliated research institute

Cobalt Strike

  • APT41 compromised Taiwanese government-affiliated research institute

DeepData

  • APT41 Deploys DeepData Framework

  • SHA-256: cf59cd171270ec9bc2baf618838eb57802cc9d48f64205da308406811dd4da92

IOC Summary

Updated arsenal of APT41

IOCs (Click to expand)
  • MD5: 5217b8552321556ea434474377cfcd02
  • MD5: b69984cbf52b418673bd08279ca845d6
  • MD5: 75bfb7d5199bf0c4e62525099b33e14f
  • MD5: bfd6286bb39a0e24a2af28c63bd8e194
  • MD5: f68ef9e40462c9760bf9c829edd9f4a9
  • MD5: 5b1e8455291d99a1724327b9a7fc2616
  • MD5: 4141c4b827ff67c180096ff5f2cc1474
  • MD5: 72070b165d1f11bd4d009a81bf28a3e5
  • MD5: b3067f382d70705d4c8f6977a7d7bee4
  • MD5: f0953ed4a679b987a2da955788737602
  • MD5: bc85062de0f70afd44bb072b0b71a8cc
  • MD5: bcac2cbda36019776d7861f12d9b59c4
  • MD5: 294cc02db5a122e3a1bc4f07997956da
  • MD5: 0d068b6d0523f069d1ada59c12891c4a
  • MD5: f062183da590aba5e911d2392bc29181

Rising from the Dust

IOCs (Click to expand)
  • domain: ns1[.]akacur.tk
  • domain: ns2[.]akacur.tk
  • domain: orange-breeze-66bb[.]tezsfsoikdvd.workers.dev
  • domain: www[.]eloples.com
  • MD5: 393065ef9754e3f39b24b2d1051eab61
  • MD5: ac125aea0b703de37980779599438b4a
  • MD5: 35f650c94faf6a2068e8238dd99edbea
  • MD5: e584119a4766e6cf49093c666965c8be
  • MD5: dc725f5e9b1ae062fbec86ee4d816b45
  • MD5: a689e182fe33b9d564dddc35412ea0a7
  • MD5: fcff642268898fcf65702a214aefbf9e
  • MD5: e98b9e21928252332edf934f3d18ac21
  • MD5: aca5c6daecf463012a09564764584937
  • MD5: 336a0d6f8cc92bf9740ce17de600463b
  • MD5: cfce85548436fb89a83bf34dc17f325d
  • MD5: e4a4aafb49b8c86a5ac087ae342c0ee6
  • MD5: 17d0ada8f5610ff29f2e8eaf0e3bb578
  • MD5: f1769ad5a9dc44794895275c656ed484
  • MD5: 8222352a61eacca3a1c6517956aa0b55
  • MD5: 9991ce9d2746313f505dbf0487337082
  • MD5: 3bb44c0dd7f424864d76d4df09538cb6
  • MD5: 0e74285f3359393e57f5d49c156aca47
  • MD5: d72f202c1d684c9a19f075290a60920f
  • MD5: 6bc4a92ff4d2cfc9da91ae6a5d2ad3d5
  • ip: 95.164.16[.]231
  • ip: 152.89.244[.]185
  • URL: hxxp[:]152.89.244.185/conn.exe

APT41 compromised Taiwanese government-affiliated research institute

IOCs (Click to expand)
  • domain: w2[.]chatgptsfit.com
  • SHA-256: 2e46fcadacfe9e2a63cfc18d95d5870de8b3414462bf14ba9e7c517678f235c9
  • SHA-256: 087c475a1b5b36b7939f5ff12dc711ba591dd2c4227ccaa28d322425ef4d0d4c
  • SHA-256: 2149d481b863bec2240ffb64c68f7fb437458885c903a7b0c21aa44f88a69d86
  • SHA-256: eba3138d0f3d2385b55b08d8886b1018834d194440691d33d612402ba8a11d28
  • SHA-256: 983f4e4be2c2cd36da67723f6e87d86994531bb1ef8e82b3fd3a1c0d6d072a0a
  • SHA-256: be7e1f1216ff707ad07d11e5d180fa1cbfba62f2e2414a20d827366bcc6be3c4
  • SHA-256: 756ceb563d9283df1fd03252aee9e9621cd2cc7ddb45f596e16660fed1dd6442
  • SHA-256: 9dc827fb1c2e3c12ee39aa5ccf3b31f64051e0cdda9d2ac54caee6b235f52640
  • SHA-256: abb2fe1f67a48b931258e47531884ca5502cec73996e686ca82eeba536258f67
  • ip: 45.85.76[.]10
  • ip: 58.64.204[.]145
  • ip: 103.96.131[.]84
  • ip: 45.85.76[.]18
  • URL: hxxps[:]www.nss.com.tw/p.ps1
  • URL: hxxps[:]www.nss.com.tw/1.hta
  • URL: hxxp[:]103.56.114.69:8085/p.ps1
  • URL: hxxp[:]45.85.76.18:443/yPc1
  • URL: hxxps[:]www.nss.com.tw/calc.exe
  • URL: hxxps[:]www.nss.com.tw/s.png

APT41 Deploys DeepData Framework

IOCs (Click to expand)
  • SHA-256: c3995f28476f7a775f4c1e8be47c64a300e0f16535dc5ed665ba796f05f19f73
  • SHA-256: b79629e820cdd36d0daed964a2c0338e125a1f90f08e226f52dc60070747c62e
  • SHA-256: b523cdd1669dbd7ab68b43fd20f30a790ec0351876a0610958b9405468753a10
  • SHA-256: ac7e20d4ddccc5e249ff0c1a72e394f9c1667a896995cf55b97b4f9fbf5de2fd
  • SHA-256: 2bfb82a43bb77127965a4011a87de845242b1fb98fd09085885be219e0499073
  • SHA-256: 041c13a29d3bee8d2e4bd9d8bde8152b5ac8305c1efcc198244b224e33635282
  • SHA-256: 735d59c0949e258501e177ec2dd5fbb60df9fa401ace08949b89077c6f0d41d0
  • SHA-256: 88e5ca44189dabb4cec8a183f6268a42f3f92b2c6d7c722d7f55efd3dc5334c8
  • SHA-256: 213520170fc7113ac8f5e689f154f5c8074dd972584b56d820c19d84b7e5b477
  • SHA-256: 724351b5cc9ad496a6c9486b8ef34772f640590a90293f913f005e994717134b
  • SHA-256: 460f1a00002e1c713a7753293b4737e65d27d0b65667b109d66afca873c23894
  • SHA-256: ccfd6ef35c718e2484b3727035d162b667f4b56df43324782d106f50ed1e3bcc
  • SHA-256: 55e2dbb906697dd1aff87ccf275efd06ee5e43bb21ea7865aef59513a858cf9f
  • SHA-256: 666a4c569d435d0e6bf9fa4d337d1bf014952b42cc6d20e797db6c9df92dd724
  • SHA-256: cf59cd171270ec9bc2baf618838eb57802cc9d48f64205da308406811dd4da92
  • SHA-256: a560931baa404189257ec9cbcc2b9449c579018218cc1d70c99b1d36dd292a0e
  • SHA-256: efff4106cfd21a356b13a5a99c626a4f103f03b9491c0f1f5e135c1e3c84e76c
  • SHA-256: 37a1ffaba2e3ea9a7b2aa272b0587826cc0b5909497d3744ec8c114b504d2544
  • domain: 119.147.213[.]48
  • domain: 202.43.239[.]13
  • domain: 103.255.176[.]176
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/frame.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/OutlookX32.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/SocialSoft.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/ChatIndexedDb.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/ProductList.dll
  • URL: hxxp[:]202.43.239.13:28992/asdgdsfdsfasd/appdata.dll
  • URL: hxxp[:]202.43.239.13:28992/asdgdsfdsfasd/ChatIndexedDb.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/WebBrowser.dll
  • URL: hxxp[:]202.43.239.13:28992/asdgdsfdsfasd/SocialSoft.dll
  • URL: hxxp[:]103.255.176.176:28992/asdgdsfdsfasd/Telegram.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/data.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/localupload.exe
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/Tdm.dll
  • URL: hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/Audio.dll
  • URL: hxxp[:]202.43.239.13:28992/asdgdsfdsfasd/SystemInfo.dll

Earth Longzhi Returns with New Tricks

IOCs (Click to expand)
  • domain: www[.]updateforhours.com
  • domain: evnpowerspeedtest[.]com
  • domain: asis[.]downloadwindowsupdate.co
  • domain: dns[.]eudnslog.com
  • SHA-256: 7910478d53ab5721208647709ef81f503ce123375914cd504b9524577057f0ec
  • SHA-256: 8327cd200cf963ada4d2cde942a82bbed158c008e689857853262fcda91d14a4
  • SHA-256: 16887b36f87a08a12fe3b72d0bf6594c3ad5e6914d26bff5e32c9b44acfec040
  • SHA-256: 21ffa168a60f0edcbc5190d46a096f0d9708512848b88a50449b7a8eb19a91ed
  • SHA-256: 39de0389d3186234e544b449e20e48bd9043995ebf54f8c6b33ef3a4791b6537
  • SHA-256: 75a51d1f1dd26501e02907117f0f4dd91469c7dd30d73a715f52785ea3ae93c8
  • SHA-256: e654ecc10ce3df9f33d1e7c86c704cfdc9cf6c6f49aa11af2826cbc4b659e97c
  • SHA-256: 4399c5d9745fa2f83bd1223237bdabbfc84c9c77bacc500beb25f8ba9df30379
  • SHA-256: 942b93529c45f27cdbd9bbcc884a362438624b8ca6b721d51036ddaebc750d8e
  • SHA-256: ebf461be88903ffc19363434944ad31e36ef900b644efa31cde84ff99f3d6aed
  • SHA-256: 9eceba551baafe79b45d412c5347a3d2a07de00cc23923b7dee1616dee087905
  • SHA-256: ef8e658cd71c3af7c77ab21d2347c7d41764a68141551938b885da41971dd733
  • SHA-256: 630bb985d2df8e539e35f2da696096e431b3274428f80bb6601bbf4b1d45f71e
  • ip: 198.13.47[.]158
  • ip: 64.227.164[.]34
  • ip: 207.148.115[.]125
  • ip: 194.31.53[.]128

Melofee: Unveiling a New Linux Threat

IOCs (Click to expand)
  • domain: help[.]git1ab.com
  • domain: stock[.]awszonwork.com
  • domain: about[.]git1ab.com
  • domain: dns[.]cloudf1are.com
  • domain: cdn4[.]cloudf1are.com
  • domain: test[.]yuanta.dev
  • domain: www[.]data-yuzefuji.com
  • domain: cloudf1are[.]com
  • domain: ssm[.]awszonwork.com
  • domain: cdn3[.]cloudf1are.com
  • domain: dgbyem[.]com
  • domain: dev[.]yuanta.dev
  • domain: update[.]ankining.com
  • domain: vt[.]livehost.live
  • domain: cdn2[.]cloudf1are.com
  • domain: us[.]securitycloud-symantec.icu
  • domain: dns2[.]cloudf1are.com
  • domain: cdn[.]cloudf1are.com
  • domain: www[.]git1ab.com
  • SHA-256: 330a61fa666001be55db9e6f286e29cce4af7f79c6ae267975c19605a2146a21
  • SHA-256: 2db4adf44b446cdd1989cbc139e67c068716fb76a460654791eef7a959627009
  • SHA-256: 2801a3cc5aed8ecb391a9638a3c6f8db58ca3002e66f11bf88f8c7c2e5a6b009
  • SHA-256: ad979716afbce85776251d51716aeb00665118fb350038d150c129256dd6fc5f
  • SHA-256: 8d855c28744dd6a9c0668ad9659baf06e5e448353f54d2f99beddd21b41390b7
  • SHA-256: 3ca39774a4405537674673227940e306cf5e8cd8dfa1f5fc626869738a489c3d
  • SHA-256: 22fd67457274635db7dd679782e002009363010db66523973b4748d5778b1a2a
  • SHA-256: 758b0934b7adddb794951d15a6ddcace1fa523e814aa40b55e2d071cf2df81f0
  • SHA-256: c36ab5108491f4969512f4d35e0d42b3d371033c8ccf03e700c60fb98d5a95f8
  • SHA-256: 3535f45bbfafda863665c41d97d894c39277dfd9af1079581d28015f76669b88
  • SHA-256: a37661830859ca440d777af0bfa829b01d276bb1f81fe14b1485fa3c09f5f286
  • SHA-256: 7684e1dfaeb2e7c8fd1c9bd65041b705bc92a87d9e11e327309f6c21b5e7ad97
  • SHA-256: 1f9e4bfb25622eab6c33da7da9be6c51cf8bf1a284ee1c1703a3cee445bc8cd9
  • SHA-256: 899ef7681982941b233e1ea3c1a6d5a4e90153bbb2809f70ee5f6fcece06cabc
  • SHA-256: 6e858c2c9ae20e3149cb0012ab9a24995aa331d2a818b127b2f517bc3aa745a0
  • SHA-256: 69ff2f88c1f9007b80d591e9655cc61eaa4709ccd8b3aa6ec15e3aa46b9098bd
  • SHA-256: 378acfdbcec039cfe7287faac184adf6ad525b201cf781db9082b784c9c75c99
  • SHA-256: 7149cdb130e1a52862168856eae01791cc3d9632287f990d90da0cce1dc7c6b9
  • SHA-256: a62b67596640a3ebadd288e733f933ff581cc1822d6871351d82bd7472655bb5
  • SHA-256: 617f9add4c27f3bb91a32fee007cce01f5a51deaf42e75e6cec3e71afe2ba967
  • SHA-256: 2e62d6c47c00458da9338c990b095594eceb3994bf96812c329f8326041208e8
  • SHA-256: f49f1b2cc52623624fdd3d636056b8a80705f6456a3d5a676e3fb78749bdd281
  • SHA-256: 407ab8618fed74fdb5fd374f3ed4a2fd9e8ea85631be2787e2ad17200f0462b8
  • SHA-256: 5861584bb7fa46373c1b1f83b1e066a3d82e9c10ce87539ee1633ef0f567e743
  • SHA-256: f3e35850ce20dfc731a6544b2194de3f35101ca51de4764b8629a692972bef68
  • SHA-256: ad5bc6c4e653f88c451f6f6375516cc36a8fa03dd5a4d1412a418c91d4f9bec8
  • SHA-256: 187b6a4c6bc379c183657d8eafc225da53ab8f78ac192704b713cc202cf89a17
  • SHA-256: a5a4284f87fd475b9474626040d289ffabba1066fae6c37bd7de9dabaf65e87a
  • SHA-256: 2c1a6fe08c8cbdc904809be4c12b520888da7f33123d1656a268780a9be45e20
  • SHA-256: 3c1842d29a3445bd3b85be486e49dba36b8b5ad55841c0ce00630cb83386881d
  • ip: 103.87.10[.]100
  • ip: 185.145.128[.]90
  • ip: 173.209.62[.]187
  • ip: 173.209.62[.]186
  • ip: 167.172.73[.]202
  • ip: 47.243.51[.]98
  • ip: 173.209.62[.]189
  • ip: 202.182.101[.]174
  • ip: 156.67.208[.]192
  • ip: 5.61.57[.]80
  • ip: 38.54.30[.]39
  • ip: 173.209.62[.]190
  • ip: 144.202.112[.]187
  • ip: 147.139.28[.]254
  • ip: 173.209.62[.]188

Espionage Campaign with Voldemort

IOCs (Click to expand)
  • domain: pants-graphs-optics-worse[.]trycloudflare.com
  • domain: recall-addressed-who-collector[.]trycloudflare.com
  • domain: invasion-prisoners-inns-aging[.]trycloudflare.com
  • domain: ways-sms-pmc-shareholders[.]trycloudflare.com
  • SHA-256: fa383eac2bf9ad3ef889e6118a28aa57a8a8e6b5224ecdf78dcffc5225ee4e1f
  • SHA-256: 3fce52d29d40daf60e582b8054e5a6227a55370bed83c662a8ff2857b55f4cea
  • SHA-256: 6bdd51dfa47d1a960459019a960950d3415f0f276a740017301735b858019728
  • SHA-256: 0b3235db7e8154dd1b23c3bed96b6126d73d24769af634825d400d3d4fe8ddb9
  • SHA-256: 561e15a46f474255fda693afd644c8674912df495bada726dbe7565eae2284fb
  • URL: hxxps[:]//od.lk/s/OTRfODQ1NzA0Mjlf/einzelfragen_steuerbescheinigungen_de.pdf
  • URL: hxxps[:]//sheets.googleapis.com:443/v4/spreadsheets/16JvcER-0TVQDimWV56syk91IMCYXOvZbW4GTnb947eE/
  • URL: hxxps[:]//pubs.infinityfreeapp.com/Notice_pour_remplir_la_N%C2%B0_2044.html
  • URL: hxxps[:]//pubs.infinityfreeapp.com/SA150_Notes_2024.html
  • URL: hxxps[:]//pubs.infinityfreeapp.com/IRS_P966.html
  • URL: hxxps[:]//od.lk/s/OTRfODQ1NDc2MjZf/SA150_Notes_2024.pdf
  • URL: hxxps[:]//od.lk/s/OTRfODQ4ODE4OThf/logo.png
  • URL: hxxps[:]//od.lk/s/OTRfODM5Mzc3NjFf/irs-p966.pdf
  • URL: hxxps[:]//resource.infinityfreeapp.com/0023012-317.html
  • URL: hxxps[:]//od.lk/s/OTRfODQ1Njk2ODVf/2044_4765.pdf
  • URL: hxxps[:]//od.lk/s/OTRfNzQ5NjQwOTJf/test.png
  • URL: hxxps[:]//resource.infinityfreeapp.com/ABC_of_Tax.html
  • URL: hxxps[:]//od.lk/s/OTRfODQ5MzQ5Mzlf/ABC_of_Tax.pdf
  • URL: hxxps[:]//pubs.infinityfreeapp.com/La_dichiarazione_precompilata_2024.html
  • URL: hxxps[:]//od.lk/s/OTRfODM3MjM2NzVf/La_dichiarazione_precompilata_2024.pdf
  • URL: hxxps[:]//pubs.infinityfreeapp.com/Steuerratgeber.html
  • URL: hxxp[:]//83.147.243.18/p/

Powershell Backdoor with Telegram C2

IOCs (Click to expand)
  • SHA-256: bb3d35cba3434f053280fc2887a7e6be703505385e184da4960e8db533cf4428
  • SHA-256: d71f6fbc9dea34687080a2e12bf326966f6841d51294bd665261e07281459eeb
  • URL: hxxps[:]//raw.githubusercontent.com/efimovah/abcd/main/xxx.gif
  • URL: hxxp[:]//ip-api.com/json

Blackfly Espionage Materials

IOCs (Click to expand)
  • domain: icy-bar-c375.microsoft-updates[.]workers.dev
  • domain: www.mircoupdate.https443[.]net
  • domain: update-chrome.realgodad.workers[.]dev
  • domain: track.cdn78544[.]ru
  • domain: www.cdn7854.workers[.]dev
  • domain: shrill-tooth-b557.vgfjuic.workers[.]dev
  • domain: www.sitennews[.]com
  • SHA-256: 0faddbe1713455e3fc9777ec45adf07b28e24f4c3ddca37586c2aa6b539898c0
  • SHA-256: 22a50cea6ad67a7e8582d2cd4cdc3eaaf57c0fbe8cd062a9b15710166e255a86
  • SHA-256: c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db
  • SHA-256: 73eaba82ef1c502448e533007e92b1afa879b09f85f28b71648668ea62839ff5
  • SHA-256: c02accc26a389397fb172f83258baa8a974986ffd706ba708a3b0a679f61be56
  • SHA-256: 83de8917bf0ac1d670acf27431015215db872b7291979312dd65e30d99806abb
  • SHA-256: 7e63c6b9ab3b32beffbc1eb23d6ca7cc59616b0722f0dd4f0d893c0a1724f5d7
  • SHA-256: 073b35ecbd1833575fbfb1307654fc532fd938482e09426cfb0541ad87a04f75
  • SHA-256: ec10a9396dca694fe64366e0dab82d046cf92457f97efd50a68ceb85adef6b74
  • SHA-256: 1c88150ec85a07c3db5f18c5eedcb0b653467b897af01d690ed996e5e07ba8e3
  • SHA-256: 8405d742405d3a6d3bda6bc49630dd5f3604a3d6ae27cbd533e425f8abbaafdc
  • SHA-256: cdcbd9c25e06ac6da5497fa19459d0007449ec1a3e6bc591334db6fb3598aecb
  • SHA-256: 166b6dcdac31f4bf51e4b20a7c3f7d4f7017ca0c30fa123d5591e25c3fa66107
  • SHA-256: a50f85c71b69563ba42bf04c937e1063244ca4957231d3adac76f1c96ab42d3c
  • SHA-256: 07aa971f0791b06dd442d4c7a49c1d3d27a1cbb16602f731e870b5ef50edf69e
  • SHA-256: 3e52c310c6556367ff9e18448bc41719e603d1cbbdafdcba736c6565529617b6
  • SHA-256: e4360c0aa995e6e896b22bb7725a6c9b189be8606e7cbbc8b6e80c606358649d
  • SHA-256: 21fc0f50d545c0a373380934dc61c423c8a31d8c3e6eae4f8a35149ad9962d88
  • SHA-256: 7f24bc080281d250ec88493e5803e488721a17c9382cd54ba8dfbcb785f23a88
  • SHA-256: 7463700ec5768d4af6549028465f978059611555aa8e22e2b7c664b1cdbfa9ae
  • SHA-256: ec5a96f42aeccdf9a3ae4c3650689606c8539fd65c0b47f30887afecb901be43
  • SHA-256: ab56501167fe689fe55f6e6ddc3bb91952299bd5c3ef004b02bf1c3b4061c7cf
  • SHA-256: e5f1360d4c299bb32e33e081115f2b520251a983af2ebc649b4b9b70308246fe
  • SHA-256: 7586e58a569c2a07d0b3a710616f48833a040bf3fc57628bbdec7fcb462d565a
  • ip: 5.182.207[.]28
  • ip: 212.87.212[.]115
  • ip: 78.108.216[.]20

Earth Baku Latest Campaign Analysis

IOCs (Click to expand)
  • domain: icy-bar-c375.microsoft-updates.workers[.]dev
  • domain: www.mircoupdate.https443[.]net
  • domain: update-chrome.realgodad.workers[.]dev
  • domain: track.cdn78544[.]ru
  • domain: www.cdn7854.workers[.]dev
  • domain: shrill-tooth-b557.vgfjuic.workers[.]dev
  • domain: www.sitennews[.]com
  • SHA-256: 0faddbe1713455e3fc9777ec45adf07b28e24f4c3ddca37586c2aa6b539898c0
  • SHA-256: 22a50cea6ad67a7e8582d2cd4cdc3eaaf57c0fbe8cd062a9b15710166e255a86
  • SHA-256: c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db
  • SHA-256: 73eaba82ef1c502448e533007e92b1afa879b09f85f28b71648668ea62839ff5
  • SHA-256: c02accc26a389397fb172f83258baa8a974986ffd706ba708a3b0a679f61be56
  • SHA-256: 83de8917bf0ac1d670acf27431015215db872b7291979312dd65e30d99806abb
  • SHA-256: 7e63c6b9ab3b32beffbc1eb23d6ca7cc59616b0722f0dd4f0d893c0a1724f5d7
  • SHA-256: 073b35ecbd1833575fbfb1307654fc532fd938482e09426cfb0541ad87a04f75
  • SHA-256: ec10a9396dca694fe64366e0dab82d046cf92457f97efd50a68ceb85adef6b74
  • SHA-256: 1c88150ec85a07c3db5f18c5eedcb0b653467b897af01d690ed996e5e07ba8e3
  • SHA-256: 8405d742405d3a6d3bda6bc49630dd5f3604a3d6ae27cbd533e425f8abbaafdc
  • SHA-256: cdcbd9c25e06ac6da5497fa19459d0007449ec1a3e6bc591334db6fb3598aecb
  • SHA-256: 166b6dcdac31f4bf51e4b20a7c3f7d4f7017ca0c30fa123d5591e25c3fa66107
  • SHA-256: a50f85c71b69563ba42bf04c937e1063244ca4957231d3adac76f1c96ab42d3c
  • SHA-256: 07aa971f0791b06dd442d4c7a49c1d3d27a1cbb16602f731e870b5ef50edf69e
  • SHA-256: 3e52c310c6556367ff9e18448bc41719e603d1cbbdafdcba736c6565529617b6
  • SHA-256: e4360c0aa995e6e896b22bb7725a6c9b189be8606e7cbbc8b6e80c606358649d
  • SHA-256: 21fc0f50d545c0a373380934dc61c423c8a31d8c3e6eae4f8a35149ad9962d88
  • SHA-256: 7f24bc080281d250ec88493e5803e488721a17c9382cd54ba8dfbcb785f23a88
  • SHA-256: 7463700ec5768d4af6549028465f978059611555aa8e22e2b7c664b1cdbfa9ae
  • SHA-256: ec5a96f42aeccdf9a3ae4c3650689606c8539fd65c0b47f30887afecb901be43
  • SHA-256: ab56501167fe689fe55f6e6ddc3bb91952299bd5c3ef004b02bf1c3b4061c7cf
  • SHA-256: e5f1360d4c299bb32e33e081115f2b520251a983af2ebc649b4b9b70308246fe
  • SHA-256: 7586e58a569c2a07d0b3a710616f48833a040bf3fc57628bbdec7fcb462d565a
  • ip: 5.182.207[.]28
  • ip: 212.87.212[.]115
  • ip: 78.108.216[.]20

APT41 Targets Gambling Sector

  • domain: time.qnapntp[.]com

CVEs Used

Earth Longzhi Returns with New Tricks

  • CVE-2018-5713

APT41 compromised Taiwanese government-affiliated research institute

  • CVE-2018-0824

YARA Rules

Windows_Trojan_DodgeBox


rule Windows_Trojan_DodgeBox_095012d2 {
    meta:
        author = "Elastic Security"
        id = "095012d2-2804-44f5-b4a1-f9d9c028daf1"
        fingerprint = "0797dbe75dea90df77d35d2d4a259b4402c041bc10f9e52df2ef80b2a5804c9f"
        creation_date = "2024-07-11"
        last_modified = "2024-07-26"
        threat_name = "Windows.Trojan.DodgeBox"
        reference_sample = "c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db"
        severity = 100
        arch_context = "x86"
        scan_context = "file, memory"
        license = "Elastic License v2"
        os = "windows"
    strings:
        $a1 = { 53 4F 46 54 57 41 52 45 5C 4D 69 63 72 6F 73 6F 66 74 5C 43 72 79 70 74 6F 67 72 61 70 68 79 00 4D 61 63 68 69 6E 65 47 75 69 64 00 2E 70 64 61 74 61 }
        $a2 = { 5C 00 4D 00 69 00 63 00 72 00 6F 00 73 00 6F 00 66 00 74 00 2E 00 4E 00 45 00 54 00 5C 00 61 00 73 00 73 00 65 00 6D 00 62 00 6C 00 79 00 5C 00 47 00 41 00 43 00 5F 00 4D 00 53 00 49 00 4C 00 5C 00 00 00 00 00 00 00 25 00 6C 00 6C 00 64 00 2E 00 6C 00 6F 00 67 }
        $a3 = { 48 83 EC 20 48 63 51 3C 48 8B D9 33 F6 48 8D 3C 11 8B 8F 90 00 00 00 85 C9 74 21 8B 87 94 00 00 00 85 C0 74 17 44 8B C0 48 03 CB 33 D2 ?? ?? ?? ?? ?? 48 89 B7 90 00 00 00 8B 53 3C 48 63 FA }
        $a4 = { 48 89 5C 24 08 48 89 74 24 10 57 48 83 EC 20 48 63 51 3C 48 8B D9 33 F6 48 8D 3C 11 8B 8F 90 00 }
        $a5 = { 48 89 5C 24 08 48 89 74 24 10 57 48 83 EC 20 48 63 59 3C 33 D2 4C 8B C3 48 8B F1 E8 }
    condition:
        any of them
}

Rising from the Dust


rule M_Hunting_Dropper_DUSTTRAP_1
{
    meta:
        author = "Mandiant"
        description = "Detects the DUSTTRAP dropper (x64) based 
on the use of CFG patching constants and argument construction 
for payload entry-point"
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    strings:
        $cfg_patch_constant_1 = { 48 FF E0 CC 90 }
        $cfg_patch_constant_2 = { 8B DA 48 8B F9 E8 }
        $cfg_patch_constant_3 = { B8 48 8B 00 00 66 39 02 }
        $cfg_patch_constant_4 = { 81 7A 07 48 8B D1 48 }

        $log_format = "%lld.log" wide

    condition:
        uint16(0) == 0x5a4d and
        all of ($cfg_patch_constant_*) and
        $log_format
}

import "pe"
 
rule M_HUNTING_DUSTTRAP_PayloadFile {
    meta:
        author = "Mandiant"
        description = "Detects executables containing a .lrsrc section 
which may represent DUSTTRAP payloads"
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    condition:
        for any i in (0..pe.number_of_sections - 1): (
            uint32(pe.sections[i].raw_data_offset + 0) == 0x100 and
            pe.sections[i].raw_data_size > uint32
(pe.sections[i].raw_data_offset + 0) and
            pe.sections[i].name == ".lrsrc" and
            uint32(pe.sections[i].raw_data_offset + 4) < 0x1000 and
            uint32(pe.sections[i].raw_data_offset + 8) < 4
        )
}

import "pe"

rule M_Hunting_DUSTPAN_CryptKeys {
    meta:
        author = "Mandiant"
        description = "Attempts to detect executables containing known 
DUSTPAN encryption keys within the .data section"
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    strings:
        $key_1 = {3BCF741BF6411C087415BA340000004C8D05F28
C0000488B4910E801F0FEFFB8}
        $key_2 = {C4498BD6488BCFE848A5000084C07564488BCFE
8585C0000498B0F4C8B497045}
        $key_3 = {A24299055F1F0C14CBDD0B01DFA64C34F5FD033
CA7F1AF30A0C75C57359D41E0}

    condition:
        filesize < 15MB and
        for any i in (0..pe.number_of_sections - 1): (
            pe.sections[i].name == ".data" and
            any of ($key_*) in (pe.sections[i].raw_data_offset..
pe.sections[i].raw_data_offset + pe.sections[i].raw_data_size)
        )
}

import "elf"
rule M_Hunting_Utility_Linux_SQLULDR2_1
{
    meta:
        author = "Mandiant"
        description = "Detection of the Linux version of SQLULDR2."
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    strings:
        $name = "sqluldr2zip.c" ascii
        $out = "uldrdata.%p.txt" ascii
        $heading = "SQL*UnLoader: Fast Oracle Text Unloader" ascii
        $p1 = "exec    = the command to execute the SQLs" ascii
        $p2 = "file    = output file name(default: uldrdata.txt)" ascii
        $p3 = "format  = MYSQL: MySQL Insert SQLs, SQL: Insert SQLs" ascii
        $p4 = "text    = output type (MYSQL, CSV, MYSQLINS, 
ORACLEINS, FORM, SEARCH)" ascii
        $p5 = "rows    = print progress for every given rows 
(default, 1000000)" ascii
        $p6 = "query   = select statement" ascii
        $p7 = "user    = username/password@tnsname" ascii

    condition:
        (uint32(0) == 0x464c457f) and 
        $name and $out and $heading and (5 of ($p*)) and
        for any i in (0 .. elf.symtab_entries): 
(elf.symtab[i].name == "OCIServerAttach") and
        for any i in (0 .. elf.symtab_entries): 
(elf.symtab[i].name == "OCISessionBegin")
}

import "pe"
import "elf"
rule M_Hunting_Utility_SQLULDR2_1
{
    meta:
        author = "Mandiant"
        description = "Detection of SQLULDR2."
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    strings:
        $win_name = "sqluldr2.exe" ascii
        $elf_name = "sqluldr2zip.c" ascii
        $out = "uldrdata.%p.txt" ascii
        $heading = "SQL*UnLoader: Fast Oracle Text Unloader" ascii
        $p1 = "exec    = the command to execute the SQLs" ascii
        $p2 = "file    = output file name(default: uldrdata.txt)" ascii
        $p3 = "format  = MYSQL: MySQL Insert SQLs, SQL: Insert SQLs" ascii
        $p4 = "text    = output type (MYSQL, CSV, MYSQLINS, 
ORACLEINS, FORM, SEARCH)" ascii
        $p5 = "rows    = print progress for every given rows 
(default, 1000000)" ascii
        $p6 = "query   = select statement" ascii
        $p7 = "user    = username/password@tnsname" ascii
        $import = "OCI.dll" ascii

    condition:
        (((uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and 
        pe.imports("OCI.dll","OCIServerAttach") and
        pe.imports("OCI.dll","OCISessionBegin") and
        $import and  $win_name and
        for all of ($p*) : ( @ > @heading )) or 
        ((uint32(0) == 0x464c457f) and 
        $elf_name and
        for any i in (0 .. elf.symtab_entries): 
(elf.symtab[i].name == "OCIServerAttach") and
        for any i in (0 .. elf.symtab_entries): 
(elf.symtab[i].name == "OCISessionBegin"))) and 
        $out and $heading and (5 of ($p*))
}

rule M_Hunting_Uploader_PINEGROVE_1
{
    meta:
        author = "Mandiant"
        description = "Hunting for PINEGROVE uploader 
malware family."
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    strings:
        $s1 = "Config: `%v`" ascii
        $s2 = "auth.json" ascii
        $s3 = "sp=%v%v%x" ascii
        $s4 = "Time: %v" ascii
        $s5 = "/me/drive/root" ascii
        $s6 = "OneDrive" ascii fullword
        $s7 = "microsoft.graph.driveItemUploadableProperties" ascii
        $s8 = "client_id=%v&client_secret=%v" ascii
        $s9 = "http://localhost/onedrive-login" ascii

    condition:
        (
            ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) or 
(uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or 
(uint32(0) == 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or 
            (uint32(0) == 0x464c457f) or 
            (uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
        ) and 
        (6 of them)
}

rule M_Hunting_Uploader_PINEGROVE_2
{
    meta:
        author = "Mandiant"
        description = "Hunting for PINEGROVE uploader 
malware family."
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    strings:
        $f1 = "main.AllFiles" ascii
        $f2 = "main.Collect" ascii
        $f3 = "main.ConfigInit" ascii
        $f4 = "main.ConfigRead" ascii
        $f5 = "main.ConfigSave" ascii
        $f6 = "main.ConfigUpdate" ascii
        $f7 = "main.Exit" ascii
        $f8 = "main.FileRange" ascii
        $f9 = "main.FileReader" ascii
        $f10 = "main.FileStatus" ascii
        $f11 = "main.FormatRemoteFilePath" ascii
        $f12 = "main.GetFileName" ascii
        $f13 = "main.GetReomtePath" ascii
        $f14 = "main.Header" ascii
        $f15 = "main.init.0" ascii
        $f16 = "main.InitFile" ascii
        $f17 = "main.IsFolder" ascii
        $f18 = "main.main" ascii
        $f19 = "main.PreLoad" ascii
        $f20 = "main.Range2Int" ascii
        $f21 = "main.RemainTime" ascii
        $f22 = "main.SessionCreate" ascii
        $f23 = "main.ShowBar" ascii
        $f24 = "main.StringChecker" ascii
        $f25 = "main.Task" ascii
        $f26 = "main.TaskFail" ascii
        $f27 = "main.ThreadUpload" ascii
        $f28 = "main.Timer" ascii
        $f29 = "main.TimeUnix" ascii
        $f30 = "main.Upload" ascii
        $f31 = "main.Upload.func1" ascii
        $f32 = "main.Uploading" ascii
        $version = "go1.13.1"

    condition:
        (
            ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) or 
(uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or 
(uint32(0) == 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or 
            (uint32(0) == 0x464c457f) or 
            (uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
        ) and 
        $version and (25 of ($f*))
}

rule M_Hunting_Uploader_PINEGROVE_3
{
    meta:
        author = "Mandiant"
        description = "Hunting for PINEGROVE uploader 
malware family."
        disclaimer = "This rule is meant for hunting and is not 
tested to run in a production environment."

    strings:
        $s1 = "RefreshToken"
        $s2 = "RefreshInterval"
        $s3 = "ThreadNum"
        $s4 = "BlockSize"
        $s5 = "SigleFile"
        $s6 = "MainLand"
        $s7 = "MSAccount"
        $anchor1 =  "driveItemUploadableProperties"
        $anchor2 =  "client_id"
        $anchor3 =  "client_secret"
        $anchor4 =  "onedrive-login"
        $anchor5 =  "authorization_code"

    condition:
        (
            ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) or 
(uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or 
(uint32(0) == 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or 
            (uint32(0) == 0x464c457f) or 
            (uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
        ) and 
        (5 of ($s*)) and 
        (4 of ($anchor*))
}

Powershell Backdoor with Telegram C2


rule APT41_Powershell_Backdoor
{
meta:
author = "seyitsec"
date = "2023-04-22"
hash =
"bb3d35cba3434f053280fc2887a7e6be703505385e184da4960e8db533cf4428"
strings:
str1= ”C:\Windows\system32\forfiles.exe /p c:\windows\system32
/m notepad.exe /c "cmd.exe /c whoami >> %appdata%\z.abcd”
str2=
”5621584862:AAGG6WcTvFu7ADpnMT42PqwOoKfTqMDQKkQ::5028607068”
str3= ”Software\Microsoft\Windows\CurrentVersion\RunOnce”
condition:
all of ($str*)
}

APT41 Deploys DeepData Framework



rule DeepData_Spy_tool {

meta:
    description = "Rule to detect LightSpy-DeepData Windows files"
    author = "The BlackBerry Research and Intelligence Team"
    last_modified = "2024-11-12"
    version = "1.0"

strings:
    $a1 = {78 6d 68 5f 6d 69 71 75 5f 6b 65 79 5c 78 6d 68 5c e5 af 86} // \xmh_miqu_key\xmh\密
    $a2 = "CodeS\\compile\\tg471\\desktop" ascii wide
    $a3 = "zyx\\dll\\ProductList\\Debug" ascii wide
    $a4 = "Users\\GT1\\source\\repos\\Audio_miqu" ascii wide
    $a5 = "\\Code\\OtherWork\\DeepDataH\\" ascii wide
    $a6 = "\\tmpWork\\deepdata-v2\\deepdata" ascii wide
    $a7 = "\\Code\\project\\MiQuH\\MiQuH" ascii wide
    $b1 = "WiFi Tool ExecuteCommand without" ascii wide
    $b2 = "\\zyx\\dll\\Dll1\\Debug" ascii wide

condition:
    uint16(0) == 0x5a4d and (filesize < 25000KB) and ((any of ($a*)) or (all of ($b*)))}

GitHub elastic Linux Melofee


rule Linux_Rootkit_Melofee_25d42bdd {
    meta:
        author = "Elastic Security"
        id = "25d42bdd-f6ee-458c-a102-7123225f0be2"
        fingerprint = "964cf1d468b829064c681c6b22bce00c4ef3536243fc5d1bac16879e0b68d9b2"
        creation_date = "2024-11-14"
        last_modified = "2024-11-22"
        threat_name = "Linux.Rootkit.Melofee"
        reference_sample = "5830862707711a032728dfa6a85c904020766fa316ea85b3eef9c017f0e898cc"
        severity = 100
        arch_context = "x86, arm64"
        scan_context = "file, memory"
        license = "Elastic License v2"
        os = "linux"
    strings:
        $str1 = "hide_proc"
        $str2 = "find_hide_name"
        $str3 = "hide_module"
        $str4 = "unhide_chdir"
        $str5 = "hide_content"
        $str6 = "hidden_chdirs"
        $str7 = "hidden_tcp_conn"
        $str8 = "HIDETAGOUT"
        $str9 = "HIDETAGIN"
    condition:
        4 of them
}

rule Linux_Trojan_Melofee_c23d18f3 {
    meta:
        author = "Elastic Security"
        id = "c23d18f3-caac-4d8a-8ecd-d1b831723648"
        fingerprint = "95bd1092104aa028b65b92d3dcf6af6deb019d00ef09e9c6570da39737fe3525"
        creation_date = "2024-11-14"
        last_modified = "2024-11-22"
        threat_name = "Linux.Trojan.Melofee"
        reference_sample = "b0abf6691e769ead1f11cfdcd300f8cd5291f19059be6bb40d556f793b1bc21e"
        severity = 100
        arch_context = "x86, arm64"
        scan_context = "file, memory"
        license = "Elastic License v2"
        os = "linux"
    strings:
        $str1 = "hide ok"
        $str2 = "show ok"
        $str3 = "kill ok"
        $str4 = "wwwwwww"
        $str5 = "[md]"
        $str6 = "87JoENDi"
    condition:
        4 of them
}

Melofee: Unveiling a New Linux Threat


rule UNK_APT_MelofeeImplant {
    meta:
        author = "Exatrack"
        date =   "2023-03-03"
        update =   "2023-03-03"
        description = "Detects the Melofee implant"
        tlp =  "CLEAR"
        sample_hash = "a5a4284f87fd475b9474626040d289ffabba1066fae6c37bd7de9dabaf65e87a,f3e35850ce20dfc731a6544b2194de3f35101ca51de4764b8629a692972bef68,8d855c28744dd6a9c0668ad9659baf06e5e448353f54d2f99beddd21b41390b7"

    strings:
        $str_melofee_implant_01 = "10PipeSocket"
        $str_melofee_implant_02 = "ikcp_ack_push"
        $str_melofee_implant_03 = "TLSSocketEE"
        $str_melofee_implant_04 = "/tmp/%s.lock"
        $str_melofee_implant_05 = "neosmart::WaitForMultipleEvents"
        $str_melofee_implant_06 = "9TLSSocket"
        $str_melofee_implant_07 = "7VServer"
        $str_melofee_implant_08 = "N5boost6detail13sp_ms_deleterI13UdpSocketWrapEE"
        $str_melofee_implant_09 = "UdpServerWrap"
        $str_melofee_implant_10 = "KcpUpdater"
        $str_melofee_implant_11 = "SelfForwardServer"

        $str_command_parsing_01 = {3? 01 00 05 00 ?? ?? ?? ?? 00 00 3? 01 00 05 00 ?? ?? 3? 05 00 04 00}
        $str_command_parsing_02 = {3? 04 00 04 00 ?? ?? ?? ?? 00 00 3? 04 00 04 00 ?? ?? 3? 05 00 01 00}
        $str_command_parsing_03 = {3? 01 00 07 00 ?? ?? ?? ?? 00 00 3? 01 00 09 00 ?? ?? ?? ?? ?? 00 3? 01 00 06 00 }

    condition:
        3 of them
}

rule UNK_APT_Melofee_Installer {
    meta:
        author = "Exatrack"
        date =   "2023-03-15"
        update =   "2023-03-15"
        description = "Detects the installer for melofee malware"
        score =   80
        tlp =  "AMBER"
        source =  "Exatrack"
        sample_hash = "758b0934b7adddb794951d15a6ddcace1fa523e814aa40b55e2d071cf2df81f0"

    strings:
        $str_melofee_installer_01 = "#Script for starting modules"
        $str_melofee_installer_02 = "#End script"
        $str_melofee_installer_03 = "/etc/intel_audio/"
        $str_melofee_installer_04 = "rm -fr /etc/rc.modules"
        $str_melofee_installer_05 = "-i <data file>      Install"
        $str_melofee_installer_06 = "cteate home folder failed"
        $str_melofee_installer_07 = "create rootkit file failed"
        $str_melofee_installer_08 = "create auto start file failed"
        $str_melofee_installer_09 = "Remove Done!" // only 3 files on VT with this :D
        $str_melofee_installer_10 = "Unkown option %c\n"

    condition:
        any of them
}

rule UNK_APT_Alien_Implant {
    meta:
        author = "Exatrack"
        date =   "2023-03-03"
        update =   "2023-03-03"
        description = "Detects an unknown implant from AlienManager family, maybe related to melofee"
        tlp =  "CLEAR"
        sample_hash = "3535f45bbfafda863665c41d97d894c39277dfd9af1079581d28015f76669b88,"

    strings:
        $str_alien_01 = "[+]  Connect %s Successed,Start Transfer..."
        $str_alien_02 = "Alloc buffer to decrypt data error, length == %d."
        $str_alien_03 = "pel_decrypt_msg data error, error"
        $str_alien_04 = "encrypt data error, length == %d."
        $str_alien_05 = "DoRecvOverlapInternal error!"
        $str_alien_06 = "Socks Listen port is %d,Username is %s, password is %s"
        $str_alien_07 = "Start port mapping error! remoteAddr=%s remotePort=%d localAddr=%s localPort=%d"
        $str_alien_08 = "OnCmdSocksStart error!"
        $str_alien_09 = "The master isn't readable!"
        $str_alien_10 = "ConnectBypassSocks proxy:%s:%d error!"
        $str_alien_11 = "ConnectBypassSocks to %s %d"
        $str_alien_12 = "now datetime: %d-%d-%d %d:%d:%d"
        $str_alien_13 = "Not during working hours! Disconnect!"
        $str_alien_14 = "Example: ./AlienReverse --reverse-address=192.168.1.101:80 --reverse-password=123456"
        $str_alien_15 = "Not during working hours! Disconnect!"
        $str_alien_16 = "SocksManager.cpp"
        $str_alien_17 = "connect() in app_connect"
        $str_alien_18 = "They send us %hhX %hhX"
        $str_alien_19 = "your input directory is not exist!"
        $str_alien_20 = "Send data to local error ==> %d.\n"

    condition:
        any of them
}

References

  • https://www.zscaler.com/blogs/security-research/dodgebox-deep-dive-updated-arsenal-apt41-part-1
  • https://www.zscaler.com/blogs/security-research/moonwalk-deep-dive-updated-arsenal-apt41-part-2
  • https://cloud.google.com/blog/topics/threat-intelligence/apt41-arisen-from-dust?hl=en
  • https://www.trendmicro.com/en_us/research/23/e/attack-on-security-titans-earth-longzhi-returns-with-new-tricks.html
  • https://www.proofpoint.com/us/blog/threat-insight/malware-must-not-be-named-suspected-espionage-campaign-delivers-voldemort
  • https://blog.talosintelligence.com/chinese-hacking-group-apt41-compromised-taiwanese-government-affiliated-research-institute-with-shadowpad-and-cobaltstrike-2/
  • https://blogs.blackberry.com/en/2024/11/lightspy-apt41-deploys-advanced-deepdata-framework-in-targeted-southern-asia-espionage-campaign
  • https://cybersrcc.com/2024/10/22/chinese-nation-state-hackers-apt41-hit-gambling-sector-for-financial-gain/
  • https://asec.ahnlab.com/ko/83732/
  • https://www.trendmicro.com/en_us/research/24/h/earth-baku-latest-campaign.html
  • https://www.darkreading.com/threat-intelligence/china-apt41-targets-global-logistics-utilities
  • https://thehackernews.com/2024/07/apt41-infiltrates-networks-in-italy.html
  • https://www.securityweek.com/chinese-hacking-group-apt41-infiltrates-global-shipping-and-tech-sectors-mandiant-warns/
  • https://social.cyware.com/news/after-clasiopa-apt41-targets-asian-materials-sector-a9b46ed4
  • https://www.security.com/threat-intelligence/blackfly-espionage-materials
  • https://cybersecuritynews.com/wp-content/uploads/2023/05/Threatmon-cyber-security-news.pdf
  • https://blog.exatrack.com/melofee/