Comfoo

Malware

⚠️ Overview

Comfoo (also tracked as ComFox) is a remote access trojan (RAT) first documented publicly in 2015 by security researchers at Palo Alto Networks and subsequently associated with Chinese state-sponsored threat groups, notably APT10 (also known as Stone Panda, MenuPass, and Red Apollo). It is typically deployed as a second-stage backdoor after initial compromise via spear-phishing or exploit kits, enabling persistent stealthy access to compromised systems.

🔧 Technical Capabilities

Comfoo uses a custom binary protocol over HTTP or HTTPS for command-and-control (C2) communication, employing encrypted payloads to evade network detection. It supports a wide range of remote commands, including file upload/download, process execution, registry manipulation, keystroke logging, and screen capture. Persistence is achieved through scheduled tasks or Windows registry Run keys, and the malware incorporates process hollowing and API hooking to evade host-based defenses. It also leverages stolen digital certificates to sign its binaries, reducing static detection rates. The C2 infrastructure often uses compromised legitimate websites as proxies, and the malware dynamically resolves domain names via a built-in domain generation algorithm (DGA) to maintain resilient communication channels.

📜 History & Notable Incidents

Comfoo was first observed in targeted campaigns against aerospace, telecommunications, and government entities in Japan, South Korea, and the United States, with early samples detected in 2014 but not publicly analyzed until 2015. In 2018, the US Department of Justice indicted two Chinese hackers (part of APT10) for using Comfoo in conjunction with other tools to infiltrate multiple global companies, including Westinghouse Electric and the US Maritime Administration (MARAD). While no specific CVEs are directly attributed to Comfoo itself, it was often dropped by exploit kits targeting CVE-2017-0199 (Microsoft Office RTF vulnerability) and CVE-2018-8174 (VBScript Engine remote code execution). The malware remains active in cyberespionage campaigns, with updated variants incorporating anti-sandbox techniques.

🔍 Detection Indicators

Known file hashes for Comfoo samples include MD5: 2a5c3f8b1e9d0c4a7f6e3b2d1c0a9f8e (example; actual hashes vary per variant). Behavioral indicators include HTTP POST requests with unique User-Agent strings such as "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0)" and periodic beaconing to domains using pseudo-random subdomains (e.g., *.static.xyz). Registry persistence keys include "HKCUSoftwareMicrosoftWindowsCurrentVersionRun" with values like "svchost" or "explorer". Network IOCs often feature SSL certificates with issuer "CN=*.comfoo.com" or self-signed certificates, and mutex names such as "Global{5A3F9E2C-8D4B-11E5-A0C0-080027DC2F7E}" have been reported in threat intelligence feeds.

☠️ Risk & Impact

Comfoo enables long-term intelligence gathering, exfiltration of sensitive documents, credentials, and intellectual property from high-value targets. Affected sectors include defense, aerospace, energy, and telecommunications, with financial losses attributed to intellectual property theft and operational disruption; the 2018 indictment cited theft of trade secrets worth hundreds of millions of dollars. The malware's stealthy persistence and custom encryption complicate forensic attribution and recovery.

🛡️ Mitigation

Defenders should enforce application whitelisting, deploy network intrusion detection signatures for Comfoo's C2 patterns (e.g., Suricata rule SID 2024893 published by Emerging Threats), and block execution of unsigned or unverified binaries using Windows Defender Application Control. Regular patching of exploited vulnerabilities (CVE-2017-0199, CVE-2018-8174) and use of multi-factor authentication mitigate initial access vectors.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.