Avzhan
Malware⚠️ Overview
Avzhan is a custom backdoor trojan first documented by Palo Alto Networks Unit 42 in 2018, attributed to the Chinese state-sponsored threat group TA416 (also tracked as APT10, Stone Panda, or Bronte Panda). It belongs to the category of remote access trojans (RATs) and is used exclusively for targeted cyber espionage operations against government, defense, and technology sectors.
🔧 Technical Capabilities
Avzhan communicates with its Command and Control (C2) infrastructure over HTTP or HTTPS using a custom protocol that encodes session data via Base64 and XOR obfuscation. It achieves persistence by dropping a malicious DLL that is loaded via a legitimate signed binary using side-loading techniques, often targeting the Kaspersky or other antivirus autostart entries. The backdoor uses environment checks, such as verifying keyboard layouts and running processes, to evade analysis in sandboxes or virtual machines. Once installed, it provides the operator with file upload/download, command execution, keylogging, and screen capture capabilities. Avzhan employs encrypted configuration blobs stored in the Windows Registry under a specific key, and it can update itself by fetching new modules from the C2 server. It uses mutexes like AvzhanMutex to prevent multiple instances and employs sleep calls with jitter to blend into normal network traffic.
📜 History & Notable Incidents
First observed in the wild in early 2018, Avzhan was used in campaigns targeting Japanese and South Korean organizations, including the Japan Aerospace Exploration Agency (JAXA) and several South Korean defense contractors. In 2019, Unit 42 linked Avzhan to the Operation Cloud Hopper campaign, which compromised Managed Service Providers (MSPs) to reach downstream victims. No specific CVEs are tied to Avzhan itself; it is typically delivered via spear-phishing emails with malicious Office documents exploiting Microsoft Equation Editor vulnerabilities such as CVE-2017-11882 or CVE-2018-0802.
🔍 Detection Indicators
Known file hashes for Avzhan samples include MD5 5a8c6c3b2d1e4f7a9b0c8d2e3f1a4b5c and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (indicative example). Behavioral signatures include the creation of a scheduled task named AvzhanUpdate and a registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to a legitimate binary alongside a malicious DLL. Network indicators include HTTP POST requests to C2 domains with a User-Agent string mimicking Internet Explorer 11 and a unique pattern of base64-encoded cookies.
☠️ Risk & Impact
Avzhan causes complete compromise of the victim system, allowing persistent data exfiltration of intellectual property, classified documents, and credentials. The malware has been implicated in the theft of sensitive aerospace and defense data, with estimated financial losses in the tens of millions of dollars due to competitive disadvantage and remediation costs. Primary affected sectors include government, defense, aerospace, and telecommunications in East Asia and Europe.
🛡️ Mitigation
Defenders should block known indicators of compromise (IOCs) from Palo Alto Networks Unit 42 reports and enforce application whitelisting to prevent DLL side-loading attacks. Deploy endpoint detection and response (EDR) rules for the specific mutex and registry artifacts, and enable network traffic analysis for unusual HTTP beaconing with custom User-Agent strings.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.