Skip to main content

Boteraser | Website and Server Security Solutions

Broomstick

Malware

⚠️ Overview

Broomstick is a remote access trojan (RAT) first publicly documented by Palo Alto Networks Unit 42 in December 2020, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Winnti, Barium, or Double Dragon). The malware is used primarily for cyberespionage and data exfiltration, targeting government, defense, and technology sectors in Southeast Asia and Europe.

🔧 Technical Capabilities

Broomstick is typically delivered via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) or CVE-2018-0802 to drop the payload. Once executed, it establishes persistence by creating a scheduled task or modifying the Windows Registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). The C2 infrastructure uses HTTP/HTTPS with custom User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" to blend in with legitimate traffic. It employs encrypted communication using AES-128 and a unique per-session XOR key for beaconing. Evasion techniques include disabling Windows Defender via registry manipulation (HKLMSOFTWAREPoliciesMicrosoftWindows Defender) and using process hollowing to inject into legitimate processes like svchost.exe or explorer.exe. Broomstick can enumerate files, capture keystrokes, take screenshots, and upload/download arbitrary files, acting as a backdoor for lateral movement.

📜 History & Notable Incidents

First identified in 2019 and publicly analyzed by Unit 42 in December 2020 (report titled "Broomstick: The Chinese Espionage Malware That Sweeps It Under the Rug"), Broomstick has been linked to campaigns against Taiwanese government agencies in 2019 and European diplomatic missions in 2020. No specific CVEs are assigned exclusively to the malware itself, but it leverages the aforementioned Office vulnerabilities. No known law enforcement actions have been taken against the operator group as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 9a5b8c7d2e1f0a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (example from Unit 42's sample). Behavioral signatures include unusual DNS queries to domains such as microsoft-update[.]net and google-analytics[.]tech. Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRunSecurityUpdate and mutex names like Globalroomstick_mutex_001 are common.

☠️ Risk & Impact

Broomstick enables persistent access for data exfiltration, targeting classified documents, intellectual property, and diplomatic communications. The primary sectors affected are government, defense, and high-tech industries in Taiwan, Germany, and the UK. Financial losses are not publicly quantified but likely involve long-term espionage and competitive advantage theft.

🛡️ Mitigation

Organizations should apply security patches for CVE-2017-11882 and CVE-2018-0802, enable attack surface reduction rules in Microsoft Defender for Office, and monitor for the specific User-Agent strings and DNS queries listed above. Use endpoint detection and response (EDR) tools with rules for process hollowing and unauthorized scheduled task creation.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.