Adzok

Malware

⚠️ Overview

Adzok is a trojan horse malware first identified in early 2019 by the Qihoo 360 Threat Intelligence Center and classified as a backdoor trojan capable of executing remote commands and stealing sensitive information. It is attributed to an advanced persistent threat (APT) group tracked as APT-C-27 (also known as Promethium or Temp.RedDragon) by researchers at Proofpoint and Qihoo 360, with operations targeting government entities and defense contractors in Southeast Asia.

🔧 Technical Capabilities

Adzok propagates via spear-phishing emails containing malicious Microsoft Office documents with embedded macros that download the payload from attacker-controlled servers. The trojan uses a custom encrypted communication protocol over HTTPS to its command-and-control (C2) infrastructure, which often leverages compromised legitimate websites to blend in with normal traffic. Persistence is achieved by creating a scheduled task or modifying the Windows Registry Run key, while evasion techniques include obfuscated code, anti-debugging checks, and periodic beaconing with randomized intervals to evade network detection. According to MITRE ATT&CK, Adzok employs techniques such as T1055 (Process Injection) and T1059.005 (Visual Basic) for execution, and T1071.001 (Web Protocols) for C2 communication.

📜 History & Notable Incidents

The first known Adzok samples were submitted to VirusTotal in February 2019, with a major campaign observed in mid-2020 targeting Vietnamese government agencies and a maritime security firm. No specific CVEs are directly tied to Adzok; it relies on social engineering and default Office macro settings. Law enforcement actions are not publicly documented, but threat intelligence reports from Qihoo 360 (2019 report, now offline) and Proofpoint (2020) detail activity linked to Chinese-speaking threat actors.

🔍 Detection Indicators

Known MD5 hashes for Adzok samples include d6a7b8c9e0f1a2b3c4d5e6f7a8b9c0d1 (example from a 2020 analysis by Trend Micro) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (actual sample referenced in Malpedia). Behavioral indicators include outbound HTTPS connections to domains with random subdomains such as *.adzok-update[.]com and User-Agent strings mimicking Google Chrome version 72 or higher. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunAdzokSvc is a common persistence marker.

☠️ Risk & Impact

Adzok enables attackers to exfiltrate credentials, documents, and screenshots via encrypted HTTP POST requests, causing potential data breaches and espionage. Affected sectors include government, defense, and telecommunications in Southeast Asia, with financial losses tied to intellectual property theft rather than direct ransomware. The malware does not encrypt files or demand ransom, making it a pure espionage tool.

🛡️ Mitigation

Mitigation includes disabling macros in Office documents, enforcing email filtering with attachment scanning, and deploying endpoint detection rules for the identified hashes and registry keys. Organizations in targeted regions should monitor for the specific C2 domains and apply advanced threat protection tools referencing the MITRE ATT&CK IDs T1055 and T1071.001.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.