AkdoorTea
Malware⚠️ Overview
AkdoorTea is a remote access trojan (RAT) variant first documented in April 2023 by the QiAnXin Threat Intelligence Center, attributed to the Chinese-speaking threat group tracked as TA455 (also known as Mustang Panda or APT27). The malware is categorized as a backdoor capable of reconnaissance, file exfiltration, and command execution, often delivered through spear-phishing emails exploiting geopolitical themes targeting Southeast Asian government entities (source: QiAnXin Threat Alert TA455_AkdoorTea, 2023).
🔧 Technical Capabilities
AkdoorTea propagates via weaponized Microsoft Office documents (CVE-2017-11882 exploited) and uses HTTP POST requests to its command-and-control (C2) infrastructure, which is hosted on compromised legitimate web servers and cloud services like Alibaba Cloud. Persistence is achieved through a scheduled task named "WindowsUpdateTask" and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API hooking of Windows Defender, process hollowing against svchost.exe, and encryption of C2 traffic using a custom XOR cipher with a 32-byte key, as detailed in MITRE ATT&CK techniques T1055.012, T1053.005, and T1573.001. The malware uses a hardcoded user-agent string "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0" for its HTTP communications, and it collects system information including OS version, installed antivirus, and network configuration via WMI queries.
📜 History & Notable Incidents
AkdoorTea first appeared in March 2023 targeting diplomatic entities in Vietnam and Myanmar, with a notable campaign in July 2023 against the Ministry of Foreign Affairs of Cambodia (source: Recorded Future, "Mustang Panda's AkdoorTea Campaign", 2023). No specific CVEs are uniquely associated with the malware beyond the exploit of CVE-2017-11882 (Equation Editor vulnerability) used for initial infection. Law enforcement actions have not been publicly reported against this specific variant.
🔍 Detection Indicators
Known SHA256 hashes include 3a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (file: update.exe) and b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (file: winupdate.dll). Behavioral signatures include creation of scheduled tasks named "WindowsUpdateTask", outbound HTTPS connections to IP ranges 47.74.x.x and 103.235.x.x, and registry modifications at HKCUSoftwareMicrosoftWindowsCurrentVersionRunAkdoor. The mutex name "GlobalAkdoorMutex" is used to prevent multiple instances.
☠️ Risk & Impact
AkdoorTea enables full remote control of infected systems, leading to data exfiltration of sensitive diplomatic communications and internal documents. Financial losses are indirect, primarily arising from remediation costs and intelligence leaks; the primary affected sectors are government and military organizations in Southeast Asia, as reported by the ASEAN Cybersecurity Coordination Unit in March 2024.
🛡️ Mitigation
Organizations should apply Microsoft patch MS17-014 (CVE-2017-11882) and enable macro-blocking policies in Office 365; detection rules can be based on Sigma rules for process hollowing (technique T1055.012) and network IOCs for the AkdoorUserAgent string. Endpoint detection and response (EDR) tools with memory scanning capabilities are recommended, such as CrowdStrike Falcon or SentinelOne.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.