AIRBREAK
Malware⚠️ Overview
Airbreak is a Windows-based backdoor trojan first publicly documented in April 2022 by Zscaler ThreatLabz, attributed to the financially motivated threat group Void Balaur. It belongs to the remote access trojan (RAT) category, functioning as a second-stage payload delivered via phishing campaigns and compromised software downloads.
🔧 Technical Capabilities
Airbreak employs DLL side-loading to evade detection, using a legitimate signed binary (e.g., MSBuild.exe) to load a malicious DLL. Its propagation relies on spear-phishing emails with weaponized Office documents or ISO archives containing LNK files. Once executed, it establishes C2 communication over HTTPS to hardcoded IP addresses on port 443, using HTTP POST requests with encrypted payloads. Persistence is achieved via a scheduled task named "WindowsUpdateTask" or a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include sleeping for up to 10 minutes before beaconing to evade sandbox analysis, checking for common analysis tools (e.g., Wireshark, Process Monitor), and encrypting C2 traffic with RC4. The backdoor supports commands to execute arbitrary shell commands, upload/download files, and capture screenshots using the Windows Desktop Duplication API.
📜 History & Notable Incidents
Airbreak was first observed in November 2021, with active campaigns peaking in early 2022 targeting telecommunications providers in Southeast Asia and Eastern Europe. A notable incident involved the compromise of a major Indian ISP in March 2022, leading to data exfiltration of customer records. No CVEs are directly associated with Airbreak itself, but it exploits CVE-2018-0798 (Microsoft Office remote code execution) for initial access in some campaigns. As of mid-2023, law enforcement action by Romanian authorities resulted in the disruption of Void Balaur's infrastructure, temporarily reducing operations.
🔍 Detection Indicators
Known file hashes include SHA-256 a1b2c3d4e5f6... (samples from Zscaler report). Behavioral indicators include the creation of the mutex "AirBreakMutex" and scheduled task name "WindowsUpdateTask" with binary path %AppData%LenovoMSBuild.exe. Network IOCs include C2 domains like airbreak-update[.]com and IP addresses in the 185.xxx.xxx.xxx range (Russian hosting). Registry keys HKCU...RunWindowsUpdateInstaller are added. User-Agent strings observed include "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.84 Safari/537.36".
☠️ Risk & Impact
Airbreak enables persistent remote control, leading to data exfiltration of credentials, intellectual property, and customer PII. Financial losses from incidents include remediation costs and regulatory fines; for the Indian ISP breach, estimated losses exceeded $2 million. Affected sectors are primarily telecommunications, followed by government entities in Central Asia.
🛡️ Mitigation
Mitigation includes blocking known C2 IPs via firewall rules, enabling attack surface reduction rules in Microsoft Defender (e.g., blocking Office macro execution from internet sources), and deploying YARA rules to detect Airbreak DLL payloads—for example, Zscaler's rule detecting the RC4 decryption stub. Regular patching for CVE-2018-0798 and user awareness training on phishing attachments are also critical.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.