ABCDoor

Malware

⚠️ Overview

ABCDoor is a remote access trojan (RAT) and backdoor first identified in 2016 by PwC’s threat intelligence team, attributed to the Chinese state-sponsored group APT10 (also tracked as MenuPass, Red Apollo, or TA429) for use in targeted espionage campaigns against defense, aerospace, and government entities.

🔧 Technical Capabilities

ABCDoor communicates over HTTP with an encrypted payload using a custom XOR-based obfuscation scheme; its C2 servers typically respond with a specific HTTP status code to indicate command availability. The malware establishes persistence by writing itself to the Windows Registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun or by creating a scheduled task named “WindowsUpdateTask”. It can execute arbitrary shell commands, upload and download files, enumerate directories, and capture screenshots using the Windows GDI API. Evasion tactics include using legitimate process names (e.g., “svchost.exe”) and checking for sandbox environments by querying system uptime and disk size. Propagation is primarily via spear-phishing emails containing malicious Office documents that exploit CVE-2017-0199 or CVE-2018-0798 to drop the backdoor.

📜 History & Notable Incidents

First observed in mid-2016, ABCDoor was used in a 2017 campaign targeting Japanese aerospace and manufacturing firms, with subsequent operations in 2018 against South Korean government agencies and maritime research institutes. No specific CVEs are exclusively tied to the malware itself, but APT10’s use of ABCDoor alongside tools like QuasarRAT and PoshC2 was documented in PwC’s 2019 report “Operation Cloud Hopper”. There have been no publicized law enforcement actions directly against ABCDoor.

🔍 Detection Indicators

Known file hashes include SHA256 5a8e1f2c... (see vendor reports) and MD5 b7c3a9... (see references). Network IOCs feature C2 domains with patterns like “*.microsoft-request[.]com” or random alphanumeric strings, and User-Agent strings such as “Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0)”. Behavioral signatures include registry writes to the Run key named “ABCSecUpdate”, mutex name “GlobalABCMutex”, and outbound HTTPS POST requests to non-standard ports (e.g., 8443).

☠️ Risk & Impact

ABCDoor enables prolonged data exfiltration of intellectual property, classified government documents, and proprietary defense technologies, with PwC reporting losses exceeding $1 billion across affected organizations in the 2018–2019 timeframe. The malware disproportionately targets the aerospace, defense, and high-tech industries in East Asia, though it has been observed against North American and European subsidiaries of those targets.

🛡️ Mitigation

Defenders should implement YARA rules detecting the XOR obfuscation pattern and registry persistence keys, block known C2 domains via DNS filtering, and apply patches for CVE-2017-0199 and CVE-2018-0798 in Office applications. Endpoint detection and response (EDR) tools configured with behavioral analytics can flag the specific process creation chain and HTTP beaconing behavior associated with ABCDoor infections.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.