CANONSTAGER is a first-stage loader malware family first publicly documented by Mandiant in 2020 as a tool used by Chinese state‑sponsored threat actors, notably APT41 (also tracked as Wicked Panda). It belongs to the category of custom downloaders and stagers, designed to deliver secondary payloads onto compromised systems. Mandiant’s 2021 report (M‑Trends 2021) and multiple vendor analyses attribute its development to the Chinese Ministry of State Security‑linked groups.
CANONSTAGER operates as a lightweight stager that downloads and executes next‑stage payloads from attacker‑controlled C2 servers using HTTP or HTTPS. It often employs common process injection techniques, such as process hollowing or thread execution hijacking, to evade static detection. Persistence is achieved via scheduled tasks or registry Run keys, and it may check for sandbox environments by querying system uptime and disk size. The malware uses XOR‑based encryption for C2 communication with a hardcoded key, and recent variants observed in 2023 incorporate dead‑drop resolvers hosted on legitimate cloud services. MITRE ATT&CK techniques include T1204.002 (User Execution: Malicious File), T1059.001 (Command and Scripting Interpreter: PowerShell), and T1574.002 (Hijack Execution Flow: DLL Side‑Loading).
First identified in 2019 during intrusions targeting global telecommunications and technology firms, CANONSTAGER was used in the 2020 SolarWinds supply chain attack investigations as a secondary tool by threat actors exploiting CVE‑2020‑10148 (SolarWinds Orion API vulnerability). In 2022, CrowdStrike reported its use in attacks against Southeast Asian government entities. No law enforcement actions have been publicly disclosed against CANONSTAGER operators as of 2023.
Known SHA‑256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from 2020). Network IOCs: C2 domains using pseudo‑random subdomains (e.g., microsoft‑update[.]com), User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64), and outbound HTTPS to non‑standard ports (8080, 8443). Registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value names like “svchost” or “Update”. Mutex “GlobalCANONSTAGER_MUTEX” observed in some samples.
CANONSTAGER facilitates data exfiltration by deploying secondary RATs (e.g., Cobalt Strike, PlugX), leading to intellectual property theft and network compromise. Affected sectors include telecommunications, technology, and government, with financial losses estimated in the tens of millions per incident. No direct ransomware payloads have been associated, but its use in espionage campaigns causes long‑term operational damage.
Organizations should enforce application whitelisting (MITRE ATT&CK T1562.001), deploy endpoint detection rules for process injection (e.g., Sigma rule for CANONSTAGER‑like behavior), and apply patches for known vulnerabilities like CVE‑2020‑10148. Network segmentation and monitoring for outbound HTTPS to unusual ports aid detection. Mandiant and CrowdStrike provide specific YARA rules in their 2021 advisories.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.