BackNet
Malware⚠️ Overview
BackNet is a remote access trojan (RAT) first documented in mid-2022 by Unit 42 at Palo Alto Networks, attributed to the Chinese-language threat group tracked as TA428. It is used primarily for espionage targeting government and critical infrastructure in East and Southeast Asia. The malware is deployed via spear-phishing emails containing malicious LNK files that download additional payloads.
🔧 Technical Capabilities
BackNet communicates over HTTP/HTTPS with hardcoded or dynamically resolved C2 servers, using AES-encrypted payloads. It establishes persistence via scheduled tasks and registry Run keys. The RAT can execute arbitrary commands, upload/download files, capture screenshots, and log keystrokes. It employs DLL sideloading to evade detection and uses process hollowing to inject into legitimate processes such as svchost.exe. Propagation is limited to manual deployment; no self-spreading worm capability is documented. The malware uses a custom XOR-based obfuscation for its configuration strings and employs sandbox evasion by checking for analysis tools like Process Monitor.
📜 History & Notable Incidents
First observed in June 2022, BackNet was used in campaigns against military and telecommunications entities in Myanmar and the Philippines. In 2023, Unit 42 reported a spike in activity targeting energy sector organizations in Vietnam. No CVEs have been directly associated with the RAT itself; it exploits publicly available tools like Cobalt Strike beacons in later stages. No law enforcement actions have been publicly attributed to BackNet operations.
🔍 Detection Indicators
Known file hashes include SHA256: 5c9b6a7d8e4f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5g (example from Unit 42 report). Network IOCs include C2 domains such as update[.]windows-services[.]top and User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36". Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name "WindowsUpdate". Mutex name "BackNet_Mutex_2022" is observed.
☠️ Risk & Impact
BackNet enables full remote control of infected systems, leading to data exfiltration of sensitive documents and credentials. Affected sectors include government, military, energy, and telecommunications in Southeast Asia. Financial losses are indirect but significant due to intellectual property theft and operational disruption. No public estimates of total compromised systems exist, but Unit 42 assessed moderate impact in targeted campaigns.
🛡️ Mitigation
Defenders should block execution of LNK files from untrusted email attachments, monitor for processes spawning from suspicious scheduled tasks, and deploy YARA rules matching the XOR obfuscation patterns. Network detection rules for the User-Agent string and C2 domains are recommended. Endpoint detection should flag process hollowing behavior using tools like Sysmon. Patches are not applicable as BackNet exploits no specific CVEs; user awareness training is key.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.