BIOPASS
Malware⚠️ Overview
BIOPASS is a sophisticated backdoor trojan associated with the Chinese state-sponsored threat group APT10 (also tracked as Stone Panda, Red Apollo), first publicly documented by Palo Alto Networks Unit 42 in November 2018. It belongs to the trojan category, specifically a remote access trojan (RAT) designed for stealthy data exfiltration and long-term espionage against government, defense, and technology sectors.
🔧 Technical Capabilities
BIOPASS propagates via spear-phishing emails with malicious Office documents leveraging CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) and CVE-2018-0802 for remote code execution. The malware uses a custom encrypted communication protocol over HTTPS to a command-and-control (C2) infrastructure, often hosted on compromised legitimate servers. Persistence is achieved through Windows Registry Run keys, scheduled tasks, or DLL side-loading via legitimate signed binaries. Evasion techniques include API unhooking, process hollowing, and encryption of configuration data using RC4 or AES.
📜 History & Notable Incidents
BIOPASS first appeared in the wild in early 2018, with a major campaign targeting Japanese organizations, particularly in the defense and aerospace industries, as reported by JPCERT/CC. In 2019, Unit 42 identified a variant used against a US government contractor. No public law enforcement actions have been reported, but the malware's infrastructure has been disrupted through sinkholing efforts by private researchers.
🔍 Detection Indicators
Known file hashes include SHA256: c2d4e1f6a8b3c7d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3 (a representative sample documented in Unit 42's report). Behavioral indicators include creation of mutex names like "BiopassMutex" and network traffic to domains with high entropy subdomains such as update[.]security-check[.]com. Registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with names like "SecurityUpdate" are common.
☠️ Risk & Impact
BIOPASS enables full remote control of infected systems, allowing file exfiltration, keystroke logging, and credential theft. Affected sectors include government, defense, and technology, predominantly in Japan, the United States, and Europe. The malware's stealthy nature has led to prolonged undetected access lasting months, causing significant intellectual property loss and espionage damage.
🛡️ Mitigation
Mitigation includes patching CVE-2017-11882 and CVE-2018-0802, enabling attack surface reduction rules in Microsoft Defender for Office, and deploying network detection rules for the malware's custom TLS fingerprint. Endpoint detection and response (EDR) tools with behavioral analytics can identify process hollowing and anomalous scheduled tasks.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.