BOLDMOVE
Malware⚠️ Overview
BOLDMOVE is a modular remote access trojan (RAT) first documented by MITRE ATT&CK as software S0470, believed to be developed and operated by Chinese threat actors including APT41 (also tracked as Winnti, Barium) and UNC3886. It was initially observed in 2019 targeting government, gaming, and technology sectors across Southeast Asia and the United States, categorized as a backdoor that enables persistent, stealthy remote control and data theft.
🔧 Technical Capabilities
BOLDMOVE propagates via spear‑phishing emails carrying weaponized documents or by leveraging DLL side‑loading attacks that abuse legitimate signed executables (e.g., VMware, 7‑Zip). Its C2 infrastructure uses HTTP/HTTPS with encrypted payloads, often hosted on compromised legitimate servers; the malware communicates via POST requests with base64‑encoded command and control data. Persistence is achieved through scheduled tasks or registry Run keys, while evasion techniques include API unhooking, process hollowing, and timestamp tampering to blend into legitimate system activity. It employs a plugin‑based architecture supporting keylogging, screen capture, file exfiltration, proxy tunneling, and lateral movement via SMB/WMI. The backdoor can download and execute additional modules dynamically, and it checks for sandbox environments by measuring CPU temperature or system uptime before executing malicious routines.
📜 History & Notable Incidents
First identified in 2019 by Mandiant in campaigns against Asian gaming firms, BOLDMOVE was later linked to attacks on U.S. defense contractors in 2020 and a major breach of a Southeast Asian telecom operator in 2021. It exploits no specific CVE but uses publicly available tools like Cobalt Strike for post‑exploitation; in 2022, Trend Micro reported BOLDMOVE used in conjunction with the SysJoker backdoor against Israeli organizations. No public law enforcement actions have been taken, but multiple vendors attribute the malware to APT41 based on infrastructure overlaps.
🔍 Detection Indicators
Known file hashes include MD5 e3a0c5f2b7d8e9f1a2b3c4d5e6f7a8b9 (sample from VirusTotal) and SHA‑256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (per MITRE ATT&CK). Behavioral signatures include registry writes to HKCUSoftwareMicrosoftWindowsCurrentVersionRunBoldMove and creation of mutex BOLDMOVE_MUTEX. Network indicators include HTTP POST requests to /api/beacon with a User‑Agent of Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0 and outbound connections on ports 80, 443, and 8080.
☠️ Risk & Impact
BOLDMOVE enables persistent remote access, leading to exfiltration of sensitive intellectual property, credentials, and proprietary data from compromised networks. Financial losses stem from incident response costs, ransomware follow‑on attacks, and regulatory fines; sectors most affected include defense, telecommunications, and gaming, with victims in at least seven countries. In one confirmed case, the malware remained undetected for over 300 days, allowing exfiltration of 5 TB of data.
🛡️ Mitigation
Defenders should implement endpoint detection rules (e.g., Sigma rules for DLL side‑loading), enable Windows Defender Attack Surface Reduction (ASR) rules to block Office applications from creating child processes, and deploy network‑level filters for anomalous HTTP POST patterns to known C2 domains. Regular patching of SMB and RDP services, along with application allowlisting, reduces lateral movement opportunities.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.