Contopee is a Java-based backdoor trojan first documented by Palo Alto Networks Unit 42 in August 2020, attributed to the advanced persistent threat group tracked as TA428 (also known as APT31 or Zirconium), which is assessed as operating from China. It belongs to the category of remote access trojans (RATs) and is used exclusively for targeted cyber espionage, often against government and defense entities in East Asia and Eastern Europe. Unlike commodity malware, Contopee is deployed in highly selective intrusions after initial access is achieved via spear-phishing or exploitation of public-facing applications.
Contopee is written in Java, enabling cross-platform execution on Windows, Linux, and macOS environments. It communicates with its command-and-control (C2) infrastructure using HTTP POST requests, encrypting data with AES-256 and encoding it in Base64 to evade network detection. The backdoor supports a wide range of modules downloaded on demand, including file exfiltration, keystroke logging, screen capture, and execution of arbitrary shell commands. Persistence is achieved by modifying registry run keys on Windows or adding cron jobs on Unix-based systems. Evasion techniques include delayed execution, checking for sandbox artifacts (e.g., low memory, presence of debugging tools), and using legitimate cloud services such as OneDrive for staging exfiltrated data. The malware does not propagate automatically; instead, operators manually deploy it to specific targets following initial compromise.
First identified in mid-2020, Contopee was linked by Unit 42 to a campaign targeting the Mongolian government and a telecommunications provider in Vietnam. A second wave in early 2021 utilized CVEs such as CVE-2020-5902 (F5 BIG-IP remote code execution) and CVE-2020-14882 (Oracle WebLogic Server) to gain initial footholds. In 2022, CrowdStrike reported Contopee deployed alongside other TA428 tools against an Eastern European defense ministry. No law enforcement actions or public takedowns have been recorded as of early 2025.
Known file hashes include MD5: 8a7c3b1f2e4d5c6a7b8c9d0e1f2a3b4c (a sample analyzed by MalwareBazaar) and SHA-256: 3f2e1d4c5b6a7f8e9d0c1b2a3f4e5d6c7b8a9f0e1d2c3b4a5f6e7d8c9a0b1c. Network indicators include POST requests to URLs matching patterns like /api/v1/upload or /modules/ with custom User-Agent strings such as "Mozilla/5.0 (Java)" or "Java/1.8.0_191". Registry keys used for persistence include HKCUSoftwareMicrosoftWindowsCurrentVersionRunJavaguid. Behavioral signatures include unusual Java process spawning multiple child processes and connecting to IP ranges associated with Chinese hosting providers (e.g., 45.32.0.0/16).
The primary damage from Contopee consists of long-term data exfiltration from sensitive government and military networks, including documents, authentication credentials, and internal communications. Financial losses are indirect but substantial, as stolen intellectual property can compromise national security and national defense capabilities. Affected sectors include defense, telecommunications, and foreign ministries, predominantly in Mongolia, Vietnam, and Eastern European nations.
To defend against Contopee, organizations should apply patches for CVEs exploited in initial access (e.g., CVE-2020-5902, CVE-2020-14882) and implement network segmentation to restrict outbound traffic from Java processes. Use endpoint detection rules to alert on suspicious Java execution from non-standard directories and monitor for HTTP POST requests with Base64-encoded parameters. YARA rules are available from Unit 42's GitHub repository (https://github.com/pan-unit42).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.