Braodo
Malware⚠️ Overview
Braodo is a modular backdoor trojan first documented in January 2020 by researchers at Palo Alto Networks Unit 42, attributed to the Chinese-speaking threat group TA428 (also tracked as RedDelta or APT27). It belongs to the category of remote access trojans (RATs) primarily used for cyber espionage, targeting government, defense, and technology sectors in Southeast Asia and the Middle East.
🔧 Technical Capabilities
Braodo propagates via spear‑phishing emails containing malicious Office documents that exploit CVE‑2017‑0199 (Microsoft Office OLE2Link vulnerability) to drop the initial payload. Once executed, the trojan establishes persistence by creating a scheduled task named “BraodoUpdate” and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRunBraodoSvc. Its command‑and‑control (C2) infrastructure uses HTTP/HTTPS with dynamic DNS domains and a custom base64‑encoded URI scheme, often appending a fixed User‑Agent string “Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”. The malware employs process injection into explorer.exe for stealth and uses a custom XOR‑based encryption for network traffic (MITRE ATT&CK IDs: T1059.003, T1566.001, T1071.001, T1055.001). It also collects system information, browser credentials, and screenshots, then exfiltrates data to the C2 server over HTTP POST requests.
📜 History & Notable Incidents
Braodo first appeared in early 2020 campaigns targeting the Vietnamese Ministry of Public Security and a Malaysian telecommunications firm. In August 2021, a wave of attacks employed a variant that exploited CVE‑2021‑34484 (Windows Kernel Information Disclosure) for privilege escalation. No law enforcement actions have been publicly reported against the operators. The malware family remains active as of 2023, with updated samples incorporating encrypted payloads and anti‑analysis checks.
🔍 Detection Indicators
Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Unit 42 report) and a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0e1f. Behavioral indicators include creation of the mutex GlobalBraodoMutex and persistent DNS queries to domains such as braodo‑update[.]com and cdn‑braodo[.]net. Network IOCs show outbound connections to port 443 with POST data containing encrypted base64 strings to paths like “/gate.php”.
☠️ Risk & Impact
Braodo can exfiltrate sensitive documents, credentials, and system logs, leading to data breaches in government and defense organizations. In the 2021 campaign against a Philippine energy company, the malware enabled lateral movement that resulted in the theft of 12 GB of strategic documents. Financial losses are estimated in the millions of dollars due to remediation costs and regulatory fines, primarily affecting public‑sector entities in Asia.
🛡️ Mitigation
Defenders should block execution of macros from untrusted sources, apply Microsoft patches for CVE‑2017‑0199 and CVE‑2021‑34484, and deploy endpoint detection rules that flag the “BraodoMutex” mutex and the specific User‑Agent string. Network‑based detections using Snort or Suricata rules for the URI pattern “/gate.php” and base64‑encoded POST bodies are recommended.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.