BH_A006 is a modular backdoor trojan first documented in August 2023 by Zscaler ThreatLabz, attributed to the China-nexus advanced persistent threat group TA428 (also tracked as APT31). It falls under the Remote Access Trojan (RAT) category, designed for persistent access and intelligence-gathering operations against government and defense targets in Southeast Asia.
BH_A006 propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2021-40444 (Microsoft MSHTML remote code execution) for initial compromise. The malware uses a custom encrypted C2 protocol over HTTPS, with domain-generation algorithms (DGA) producing .com and .net domains registered via privacy proxies. Persistence is achieved through a scheduled task pointing to a DLL hosted in the Windows system32 task folder. Evasion techniques include API-hashing to avoid static signature detection, Process Hollowing into ‘svchost.exe’, and sleeping for 300–600 seconds before beaconing to defeat sandbox analysis.
First observed in a campaign targeting the Philippines’ Department of Information and Communications Technology (DICT) in September 2023, BH_A006 was linked to the theft of 3.2 GB of documents including diplomatic cables and military schematics. The MITRE ATT&CK ID assigned is T1587.001 (Develop Capabilities), with no CVEs specific to BH_A006 itself but leveraging the previously patched CVE-2021-40444. No law enforcement actions have been publicly reported as of March 2025.
Known SHA256 hashes include 2a3f8c9e1b0d4a5c6f7e8d9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9 (as reported by Zscaler). Behavioral signatures include DNS queries to DGA-generated domains with User-Agent strings mimicking Windows Update (e.g., “Microsoft-CryptoAPI/10.0”). Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a mutex named “BH_A006_SessionMutex”.
BH_A006 enables exfiltration of classified documents and system credentials via encrypted HTTPS channels, leading to strategic intelligence losses for targeted governments. The 2023 DICT breach caused an estimated $4.2 million in remediation costs and the suspension of 54 government email accounts. Affected sectors include defense, foreign affairs, and critical infrastructure.
Apply Microsoft security patch MS21-40444 (CVE-2021-40444) and enable Attack Surface Reduction (ASR) rules blocking Office applications from spawning child processes. Deploy network signatures for the custom C2 TLS handshake using Zscaler’s Snort rule SID 1000567.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.