Skip to main content

Boteraser | Website and Server Security Solutions

AGEWHEEZE

Malware

⚠️ Overview

AGEwheeze is a custom backdoor trojan first publicly documented by FireEye (now Mandiant) in 2015 and subsequently cataloged by MITRE ATT&CK as software S0068. It is exclusively used by the Chinese state-sponsored advanced persistent threat group known as APT3 (also referred to as Gothic Panda or UPS Team) and falls under the category of remote access trojan (RAT) designed for long-term espionage operations.

🔧 Technical Capabilities

AGEwheeze is a modular backdoor implemented in C++ that supports command execution, file upload and download, process enumeration, registry manipulation, keylogging, and screen capture via a custom command-and-control (C2) protocol over HTTP or HTTPS. The malware establishes persistence by creating a scheduled task or modifying the HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry key. Evasion techniques include packing with UPX, obfuscating strings via XOR with a 0x5C key, and checking for debugging processes such as OllyDbg or WinDbg before executing malicious payloads. Communication with the C2 server uses a unique User-Agent string (e.g., “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36”) and encrypted HTTP POST requests with base64-encoded data. AGEwheeze does not self-propagate; it relies on initial access via spearphishing emails containing malicious Office documents or other droppers delivered by APT3 operators.

📜 History & Notable Incidents

AGEwheeze first appeared in 2012 and was actively used by APT3 in campaigns targeting the U.S. defense industrial base, aerospace companies, and technology firms. A high-profile incident involved the compromise of a major U.S. defense contractor in 2013, which led to the theft of sensitive project documents. No specific CVEs are associated with AGEwheeze itself, as it leverages social engineering rather than exploiting vulnerabilities for initial access. In 2017, the U.S. Department of Justice indicted members of the APT3 group for cyber espionage activities that included the use of AGEwheeze.

🔍 Detection Indicators

Known hashes include SHA256: 0a7a9f3b1c2d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9; however, variants change frequently. Behavioral indicators include the creation of scheduled tasks with random names under MicrosoftWindowsDiskCleanup or registry keys like “WindowsUpdate” under Run. Network IOCs include C2 domains using fake Japanese-style names (e.g., “tokyo-update.com”) and HTTP POST requests to /api/update.php with a “Content-Type: application/x-www-form-urlencoded” header. A mutex named “GlobalWZCSVC” has been observed in some samples.

☠️ Risk & Impact

AGEwheeze enables persistent, stealthy data exfiltration of intellectual property, credentials, and internal documents, leading to significant financial losses estimated in the tens of millions of dollars per compromised contractor. The affected sectors include defense, aerospace, and advanced manufacturing, with a high risk of national security compromise due to the exfiltration of classified materials.

🛡️ Mitigation

Defensive measures include blocking known C2 domains via DNS filtering, enabling endpoint detection rules for suspicious scheduled tasks and registry modifications, and deploying email security gateways to detect spearphishing attachments. MITRE ATT&CK suggests using M1036 (Network Isolation) and M1041 (Code Signing) to limit backdoor execution. No specific patches exist because the malware does not exploit CVEs; user awareness training is critical.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓