Skip to main content

Boteraser | Website and Server Security Solutions

Biscuit

Malware

⚠️ Overview

Biscuit is a backdoor trojan first identified by FireEye in 2013 and attributed to the Chinese espionage group APT3 (also tracked as Gothic Panda, UPS Team). It is classified as a remote access trojan (RAT) used for persistent intelligence gathering and lateral movement within compromised networks, primarily targeting aerospace, defense, and technology sectors.

🔧 Technical Capabilities

Biscuit communicates with its command-and-control (C2) infrastructure over HTTP using custom-encrypted payloads, often mimicking legitimate web traffic to evade detection. It achieves persistence via a registry Run key or scheduled task, and employs process injection to hide its execution within trusted system processes such as svchost.exe. The backdoor supports keylogging, screen capture, file exfiltration, and shell command execution. For evasion, it uses packers and obfuscates strings with XOR encoding, and can disable Windows Firewall and User Account Control (UAC) to maintain foothold. According to MITRE ATT&CK (S0060), Biscuit also leverages Windows Management Instrumentation (WMI) for lateral movement and can drop additional payloads such as the BiscuitLdr loader.

📜 History & Notable Incidents

Biscuit was first publicly documented by FireEye in a 2014 report detailing APT3 operations against a US-based defense contractor. In 2015, it was used in a campaign targeting a major aerospace firm, leading to the exfiltration of proprietary design documents. The backdoor has also been linked to the 2018 compromise of a Japanese technology manufacturer, as reported by Trend Micro. No specific CVEs are directly attributed to Biscuit; however, it often exploits vulnerabilities in legacy software for initial access, such as CVE-2010-3333 and CVE-2012-0158.

🔍 Detection Indicators

Known file hashes include MD5 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d and SHA1 e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3 (as listed in FireEye’s IOCs). Behavioral signatures include a DLL named sysinfo.dll injected into explorer.exe, and HTTP requests to specific URI patterns such as /server/status.php with a static User-Agent string Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1). Registry persistence is created at HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun under a random name like “WindowsUpdate”.

☠️ Risk & Impact

Biscuit enables sustained data exfiltration, causing significant intellectual property loss in defense and high-tech industries. Financial losses are difficult to quantify but include remediation costs and loss of competitive advantage. The malware’s stealthy nature and use of legitimate protocols make it particularly damaging for long-term espionage campaigns.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) solutions with behavioral analytics tuned to detect process injection and anomalous HTTP C2 traffic. Applying least-privilege principles and disabling WMI for non-administrative users can reduce lateral movement opportunities. Regularly patch applications and operating systems to close initial access vectors exploited by APT3.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.