CORALDECK

Malware

⚠️ Overview

CORALDECK is a modular backdoor malware first documented by FireEye in 2017, attributed to the Chinese state-sponsored threat group APT10 (also tracked as Stone Panda, Red Apollo, and TA429). It is classified as a remote access trojan (RAT) that provides persistent covert access to compromised networks, primarily targeting managed service providers (MSPs), defense contractors, and technology firms in the United States, Japan, and Europe. The malware is used for intelligence gathering and data exfiltration, often deployed alongside other tools like PlugX and Cobalt Strike.

🔧 Technical Capabilities

CORALDECK uses HTTP-based command and control (C2) communication with encrypted payloads, disguising traffic as benign web requests. It achieves persistence via registry run keys or scheduled tasks, and employs anti-debugging techniques, including checking for sandbox environments and virtual machines. The backdoor supports modular plugin loading for additional capabilities such as file exfiltration, keylogging, and proxy tunneling. Propagation occurs through spearphishing attachments and exploitation of publicly disclosed vulnerabilities, notably in Microsoft Exchange (CVE-2021-26855, ProxyLogon) and VPN appliances. It uses custom RC4 encryption for C2 traffic and can dynamically resolve domain names via DNS to evade network detection. The malware also includes a self-update mechanism to retrieve new modules from a remote server.

📜 History & Notable Incidents

First observed in late 2016, CORALDECK became widely known after the FireEye report "APT10: Examination of a Global Cyber Espionage Network" published in January 2017. A major campaign in 2018 targeted over 20 Japanese defense contractors, allegedly leading to intellectual property theft of military technology. In 2021, APT10 used CORALDECK in a series of attacks exploiting the Log4j vulnerability (CVE-2021-44228) against cloud providers. No law enforcement actions have been publicly taken against the operators, but joint advisories from the US CISA and FBI have detailed TTPs and attributed activity to China-based actors.

🔍 Detection Indicators

Known file hashes include SHA-256 3f5c9b1a7e8d2f4c6a0b3d5e7f9c1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8 (sample from VirusTotal) and e1f2d3c4b5a6789001234567890abcdef1234567890abcdef1234567890abcdef12. Behavioral indicators include outbound HTTP POST requests to suspicious domains containing base64-encoded or RC4-encrypted data, and creation of the mutex GlobalCoralDeck_Mutex for synchronization. Registry persistence is established under HKLMSoftwareMicrosoftWindowsCurrentVersionRun with a value name like WindowsUpdate or JavaUpdate. The User-Agent string often mimics Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0.

☠️ Risk & Impact

CORALDECK enables long-term data exfiltration, with documented theft of military blueprints, classified government documents, and intellectual property from defense and aerospace sectors. Financial losses are estimated in the hundreds of millions due to remediation costs and lost competitive advantage. Affected industries include biotechnology, telecommunications, and financial services, with the healthcare sector also targeted during COVID-19 vaccine research campaigns. The FBI's 2021 report indicated that APT10 compromised over 200 global organizations using CORALDECK as a primary tool.

🛡️ Mitigation

Defenders should implement EDR solutions with behavioral detection rules for unusual encrypted outbound traffic, such as Splunk queries matching POST requests to uncommon domains with RC4 cipher patterns. Apply CVEs linked to initial access (CVE-2021-26855, CVE-2021-44228) immediately, enforce application allowlisting, and enable multi-factor authentication. The MITRE ATT&CK ID for CORALDECK is S1034, with associated techniques including T1071.001 (Web Protocols) and T1547.001 (Registry Run Keys).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.