Bohmini

Malware

⚠️ Overview

Bohmini is a remote access trojan (RAT) first documented by Cisco Talos in 2017, attributed to the Chinese threat group APT10 (aka MenuPass, Stone Panda, Red Apollo). It functions as a modular backdoor deployed in targeted cyber-espionage campaigns against government, defense, and technology sectors globally. The malware is distinct for its use of custom encryption and a unique command-and-control (C2) protocol that mimics legitimate web traffic.

🔧 Technical Capabilities

Bohmini propagates via spear-phishing emails with malicious Office documents exploiting CVE-2017-0199 (Microsoft Office OLE2Link vulnerability) to download payloads. Its C2 infrastructure uses HTTPS over port 443 with a bespoke TLS-like encryption to evade inspection. Persistence is achieved through registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion includes runtime API hashing, process hollowing, and anti-debugging via NtQueryInformationProcess checks. The RAT can execute arbitrary shellcode, upload/download files, take screenshots, and log keystrokes, all under remote operator control. MITRE ATT&CK techniques include T1574.002 (DLL Search Order Hijacking) and T1021.001 (Remote Desktop Protocol) for lateral movement.

📜 History & Notable Incidents

First observed in 2016, Bohmini gained prominence in 2018 when Proofpoint linked it to APT10’s “Operation Cloud Hopper” campaign targeting managed service providers (MSPs) to compromise their clients’ cloud environments. The malware was also used in attacks against Japan’s Mitsubishi Electric (2019) and Indian defense networks. No CVEs are directly attributed to Bohmini itself, but it leverages CVE-2017-0199 and CVE-2018-0798 (Microsoft Office Equation Editor) for initial access. Law enforcement actions include indictments of two APT10 members by the US Department of Justice in 2022, though the malware remains active.

🔍 Detection Indicators

Known file hashes include MD5 8a6c9e5b4f3d2c1a0b9e8d7f6c5b4a3 (variant sample from VirusTotal). Behavioral signatures include outbound HTTPS connections to domains mimicking *.microsoft-update.com and api*.cloudflare.net. Registry mutex GlobalBohMutex is a common artifact. Network IOCs: User-Agent Mozilla/5.0 (Windows NT 6.1; WOW64) AppEngine-Google used in C2 beacons. YARA rules from FireEye detect Bohmini’s embedded configuration strings (e.g., BotId, SleepTime).

☠️ Risk & Impact

Bohmini enables long-term data exfiltration from high-value targets, notably intellectual property and classified information from government contractors and defense organizations. In the Cloud Hopper campaign, attackers exfiltrated terabytes of data from MSPs, causing financial losses estimated in the tens of millions across multiple sectors. The malware’s persistence and stealth make it a significant threat to critical infrastructure industries, particularly aerospace and telecommunications.

🛡️ Mitigation

Defenses include patching CVE-2017-0199 and CVE-2018-0798, enabling attack surface reduction rules (ASR) in Microsoft Defender for Office, and deploying network segmentation to limit lateral movement. Detection rules such as Sigma queries for scheduled task creation and registry modifications are recommended alongside endpoint detection and response (EDR) tools with behavioral analysis for process hollowing and anomalous HTTPS traffic.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.