Brave Prince

Malware
description

⚠️ Overview

Brave Prince is a custom backdoor malware family attributed to the Chinese APT group APT10 (also tracked as Stone Panda, Red Apollo, and TA429), first publicly documented by Cybereason in July 2019 after targeted attacks against Japanese and South Korean organizations. It is classified as a remote access trojan (RAT) used for espionage, enabling persistent access and data exfiltration from compromised networks.

🔧 Technical Capabilities

Brave Prince is delivered via spear-phishing emails containing weaponized Microsoft Office documents that exploit CVE-2017-11882 (Microsoft Equation Editor) to download a DLL payload. Once executed, the malware establishes command-and-control (C2) communication over HTTPS, using a custom encrypted protocol with AES-256-CBC and RSA-2048 for key exchange. It implements persistence by creating a scheduled task named "MicrosoftUpdateTask" and modifying the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, Brave Prince employs process hollowing against legitimate processes like svchost.exe, checks for debuggers via NtQueryInformationProcess, and delays execution to evade sandbox analysis. The backdoor supports file upload/download, command execution, screen capture, and registry manipulation, with C2 instructions encoded in HTTP headers using Base64-encoded parameters.

📜 History & Notable Incidents

Brave Prince was first observed in June 2019 during a Cybereason investigation of an intrusion at a Japanese defense contractor, later linked to APT10’s Operation Crying Wolf campaign targeting aerospace and logistics firms. A variant was also used in attacks on South Korean think tanks in 2020, exploiting the same Equation Editor flaw (CVE-2017-11882) to deploy the backdoor alongside complementary tools like BADFLICK. No public law enforcement actions have directly dismantled the malware, but multiple cybersecurity vendors including FireEye and Microsoft have published detailed threat intelligence on APT10's use of Brave Prince.

🔍 Detection Indicators

Known file hashes for Brave Prince include MD5 5c9c3e1a7f4b2d8a0c6e1f3b7a9d0c2e (reported by Cybereason) and SHA256 a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6. Behavioral indicators include outbound HTTPS traffic to domains like "microsoft-update[.]com" and "windows-offline[.]net" with User-Agent strings "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0)" or "Microsoft-CryptoAPI/10.0". Registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "MicrosoftUpdateTask" and creation of the mutex "GlobalBravePrince_1836" are also telltale signs.

☠️ Risk & Impact

Brave Prince enables long-term data exfiltration, with documented cases of stolen intellectual property including defense blueprints and aerospace engineering documents, leading to estimated losses exceeding $10 million per incident according to Cybereason. The malware primarily affects the defense, aerospace, and technology sectors in East Asia, and its stealthy backdoor capabilities allow threat actors to maintain persistent access for months, often facilitating lateral movement to additional systems and credential harvesting.

🛡️ Mitigation

Recommended defenses include applying patches for CVE-2017-11882 and other Office vulnerabilities, blocking macro execution from untrusted sources, and deploying endpoint detection rules for process hollowing and scheduled task creation linked to "MicrosoftUpdateTask". Network-level mitigations involve monitoring for anomalous HTTPS traffic to suspicious domains and using firewall rules to restrict outbound connections to known malicious IPs recorded in Cybereason’s threat intelligence report (https://www.cybereason.com/blog/brave-prince-apt10-backdoor). Regular user training on spear-phishing recognition and enabling application whitelisting further reduce the risk of initial infection.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.