BioSet
Malware⚠️ Overview
BioSet is a modular remote access trojan (RAT) first documented by Mandiant in May 2022, attributed to the suspected Chinese state‑sponsored group UNC1151 (also tracked as TA416). It belongs to the backdoor category and is designed for intelligence‑gathering operations, primarily targeting government and diplomatic entities in Europe and Asia.
🔧 Technical Capabilities
BioSet propagates via spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2021‑40444 (MSHTML remote code execution) or CVE‑2022‑30190 (Follina) to drop the initial payload. The malware uses HTTP/HTTPS for command‑and‑control communication, often employing DNS over HTTPS (DoH) to evade network detection. Persistence is achieved through scheduled tasks or Windows Registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it implements sandbox detection by checking for debugger processes and virtual machine artifacts, and it encrypts its configuration using AES‑256. The RAT can execute arbitrary shell commands, upload/download files, and enumerate network resources, with a built‑in proxy capability to pivot within compromised environments.
📜 History & Notable Incidents
First observed in early 2021, BioSet gained prominence in June 2022 when Mandiant published a detailed report linking it to campaign activities against the Ukrainian government during the Russian‑Ukrainian conflict. Notable victims include the Ukrainian Ministry of Defense and a Baltic state foreign ministry. No specific CVEs are tied to the malware itself, but the exploit chain relies on CVE‑2021‑40444 and CVE‑2022‑30190, both patched by Microsoft. No law enforcement actions have been publicly reported against the operators.
🔍 Detection Indicators
Known file hashes for BioSet samples include SHA‑256 3a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0 (from VirusTotal). Behavioral indicators include outbound HTTP requests to non‑standard ports (e.g., 8443, 9001) with a User‑Agent string of Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0. Registry persistence key HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdateChecker is commonly created. Network IOCs include connections to domains mimicking legitimate security software (e.g., update‑mcafee[.]com).
☠️ Risk & Impact
BioSet facilitates long‑term intelligence exfiltration, stealing credentials, email archives, and sensitive documents from compromised systems. Financial losses are primarily indirect—operational disruption and geopolitical leverage. Affected sectors include government, defense, and diplomatic missions, with European and Asian institutions being the most targeted.
🛡️ Mitigation
Apply Microsoft patches for CVE‑2021‑40444 and CVE‑2022‑30190 immediately. Enable network detection rules for anomalous HTTP User‑Agent strings and block outbound connections to known malicious domains listed in Mandiant’s IOC feed. Deploy EDR tools with behavior‑based detection for process injection and scheduled task creation, and restrict macro execution in Office documents.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.