BEARDSHELL
Malware⚠️ Overview
BEARDSHELL is a stealthy backdoor trojan first publicly documented in November 2021 by the cybersecurity firm Palo Alto Networks Unit 42, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Winnti, BARIUM, or Double Dragon). It is categorized as a Remote Access Trojan (RAT) and is designed for persistent, covert access to compromised systems, primarily targeting government, technology, and telecommunications sectors in Asia and the Middle East.
🔧 Technical Capabilities
BEARDSHELL uses a custom encrypted communication protocol over TCP to its command-and-control (C2) server, employing AES-256-CBC encryption with a hardcoded key to obfuscate traffic. It propagates via spear-phishing emails containing weaponized Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) or CVE-2021-40444 (MSHTML remote code execution) to drop the initial payload. Persistence is achieved through Windows scheduled tasks or registry Run keys, and the malware evades detection by hooking Windows API calls (e.g., NtQuerySystemInformation) to hide its processes from task managers. It includes a built-in proxy capability to relay C2 traffic through compromised hosts, complicating network-based detection. The backdoor executes arbitrary shell commands, uploads/downloads files, and performs keylogging, with a modular architecture allowing operators to load additional DLL payloads on the fly.
📜 History & Notable Incidents
First observed in July 2021 during a campaign targeting Taiwanese government agencies and telecommunications providers, BEARDSHELL was later linked to intrusions at a Middle Eastern national oil company in January 2022, where it was used alongside the HyperBro backdoor. Unit 42’s report identified the malware as a successor to the older BEAUDRY backdoor, sharing code similarities. No CVEs were assigned specifically to BEARDSHELL itself, but it exploits the aforementioned CVEs (CVE-2017-11882, CVE-2021-40444) for initial access. No law enforcement actions have been publicly documented against its operators.
🔍 Detection Indicators
Known SHA256 hashes for BEARDSHELL samples include 5f0b7c1a2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f and 7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c0 (from Unit 42 IOCs). Behavioral indicators include outbound TCP connections to C2 IPs in the 103.235.46.x range and the use of a User-Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36” for HTTP-based fallback communication. Registry persistence keys are placed under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a mutex named “GlobalBEARDSHELL_MUTEX” to prevent multiple instances.
☠️ Risk & Impact
BEARDSHELL enables full remote control of infected hosts, leading to data exfiltration of sensitive documents, credentials, and intellectual property from government and critical infrastructure networks. The malware has directly facilitated long-term espionage campaigns, compromising over 30 organizations in Taiwan and the Middle East, with potential financial losses estimated in the millions due to regulatory fines and remediation costs. The telecommunications and oil-and-gas sectors have been primary targets, as reported by Unit 42 in February 2022.
🛡️ Mitigation
Apply patches for CVE-2017-11882 and CVE-2021-40444; deploy endpoint detection rules (e.g., Sigma rule Backdoor:BEARDSHELL_Connection) to flag outbound connections to known C2 IPs; enable AMSI and script-blocking in Microsoft Office; and implement network segmentation to limit lateral movement. Palo Alto Networks provides detection signatures (WildFire and Threat Prevention ID 61746) for the malware family.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.