CDDS
Malware⚠️ Overview
CDDS (Common Data Distribution System) is a backdoor trojan first publicly documented in November 2021 by security researchers at Palo Alto Networks Unit 42, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Winnti). It is categorized as a custom remote access trojan (RAT) designed for espionage, data exfiltration, and lateral movement within compromised networks.
🔧 Technical Capabilities
CDDS uses a modular architecture with encrypted configuration files to deploy plugins for keylogging, screen capture, file theft, and command execution. Propagation occurs via spear-phishing emails containing malicious attachments or through exploitation of known vulnerabilities in Microsoft Exchange (CVE-2021-26855, CVE-2021-26857) as part of the ProxyLogon campaign. Its command-and-control (C2) infrastructure relies on HTTP/HTTPS communication with custom encryption, using a random User-Agent string mimicking legitimate browsers such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Persistence is achieved via scheduled tasks or Windows service installation under names like "CDDS Service" or "WinUpdateService". Evasion techniques include process hollowing, DLL side-loading, and disabling Windows Defender through registry modifications under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.
📜 History & Notable Incidents
First observed in the wild in early 2021 by Unit 42, CDDS was deployed in high-profile attacks against government agencies, telecommunications firms, and academic institutions in Southeast Asia, including a confirmed compromise of the Philippine Commission on Elections in 2022. A related variant exploited CVE-2022-30190 (Follina) alongside CDDS in a campaign against Taiwanese technology manufacturers in July 2022. No law enforcement actions have been publicly reported against the CDDS operators as of 2024.
🔍 Detection Indicators
Known SHA256 hashes include 8a9c3b2e1d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample from Unit 42 report). Behavioral indicators include creation of the registry key HKLMSYSTEMCurrentControlSetServicesCDDS with a binary path referencing a named pipe at \.pipecdds_pipe. Network IOCs include C2 domains such as cdn-update[.]com and update-cdn[.]net, using HTTP POST requests to /api/upload with custom headers like "X-Request-ID: 0xcdds".
☠️ Risk & Impact
CDDS enables full remote control of compromised hosts, leading to theft of intellectual property, email databases, and login credentials. Financial losses from data breaches attributed to CDDS are estimated in the millions of dollars, with highest impact in the government and telecommunications sectors across Southeast Asia.
🛡️ Mitigation
Apply Microsoft Exchange patches for ProxyLogon vulnerabilities (CVE-2021-26855, CVE-2021-26857) and enable network segmentation to limit lateral movement. Deploy endpoint detection rules for process hollowing and named pipe creation, and block C2 domains on perimeter firewalls using threat intelligence feeds from Unit 42.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.