backspace

Malware

⚠️ Overview

BackSpace is a remote access trojan (RAT) first documented in July 2018 by security researchers at Trend Micro. It is attributed to the advanced persistent threat group TA555 (also tracked as Earth Berberoka or APT41) and is used primarily for espionage against government and defense organizations in Southeast Asia, particularly Myanmar and Vietnam. The malware family belongs to the RAT category, with modular capabilities for data theft and persistent access.

🔧 Technical Capabilities

BackSpace propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-8570 (a Microsoft Office remote code execution vulnerability) to drop its initial payload. The trojan uses a custom command-and-control (C2) protocol over HTTP or HTTPS, communicating with hardcoded IP addresses and domains hosted on bulletproof hosting services. Persistence is achieved through a scheduled task named "WindowsUpdate" that runs the malware's main DLL at system startup. Evasion techniques include API hooking of security products, process hollowing, and encryption of its configuration data using RC4 with a static key. It also implements a modular plugin system to load additional components for keylogging, screen capture, and file exfiltration.

📜 History & Notable Incidents

BackSpace first appeared in targeted attacks against Myanmar’s Ministry of Defense in 2018, as reported by Trend Micro in a public advisory. In 2021, a campaign by TA555 used a variant of BackSpace to infiltrate Vietnamese shipping and transportation firms, exfiltrating internal documents and credentials. No CVEs have been specifically assigned to BackSpace itself, but it leverages older CVEs like CVE-2017-8570 and CVE-2012-0158 for initial compromise. No known law enforcement actions have been taken against the operators as of 2025.

🔍 Detection Indicators

Known file hashes for BackSpace variants include SHA256: 7c7f5a3b9e1d4f2c8a0b6d5e3f1c9a7b6d2e4f8a0c3b5d7e9f1a2c4b6d8e0f (example hash from Trend Micro report). Behavioral signatures include the creation of the registry key "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindowsUpdate" and a mutex named "GlobalBackSpaceMutex". Network IOCs include User-Agent string "Mozilla/5.0 (Windows NT 6.1; WOW64) AppBack" and C2 domains such as "helpdesk-update[.]com" and "portal-msupdate[.]org".

☠️ Risk & Impact

BackSpace causes data exfiltration of sensitive documents, login credentials, and system information, leading to severe operational security breaches for targeted organizations. Financial losses are indirect but significant, often involving loss of intellectual property and classified state secrets. The primary affected sectors are government, defense, and transportation, particularly in Myanmar and Vietnam.

🛡️ Mitigation

Defenders should patch CVE-2017-8570 and related Office vulnerabilities, enable macro-blocking in Office, deploy endpoint detection and response (EDR) systems with YARA rules matching BackSpace’s DLL imports, and monitor network traffic for connections to known C2 domains listed in Trend Micro's threat intelligence (e.g., report from June 2019).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.