Curator
Malware⚠️ Overview
Curator is a sophisticated modular backdoor first documented by Palo Alto Networks Unit 42 in January 2018, attributed to a Chinese state-sponsored threat group tracked as APT10 (also known as Stone Panda or Red Apollo). It belongs to the category of advanced persistent threat (APT) malware, specifically a remote access trojan (RAT) designed for espionage and data exfiltration against defense and technology sectors globally.
🔧 Technical Capabilities
Curator uses custom encrypted communication over HTTP to its command‑and‑control (C2) infrastructure, with traffic disguised as legitimate web requests using a unique User‑Agent string. It employs multiple persistence mechanisms, including registry Run keys and Windows service DLL hijacking, and can load plugins dynamically to perform keylogging, screen capture, and file theft. The malware evades detection by encrypting its configuration data with a hardcoded XOR key and by leveraging process injection into legitimate system processes such as svchost.exe. Propagation occurs primarily through spear‑phishing emails containing weaponized Office documents that drop the initial payload, and the C2 protocol uses domain‑generation algorithms (DGAs) to avoid sinkholing.
📜 History & Notable Incidents
Curator was first observed in mid‑2017 targeting Japanese and European defense contractors, with a major campaign in 2018 against US aerospace firms. No CVEs are directly associated with Curator itself, but the delivery documents exploit Microsoft Office vulnerabilities including CVE‑2017‑0199 and CVE‑2017‑11882. Law enforcement actions have not publicly targeted the operators, but multiple private‑sector reports (e.g., Unit 42, Dragos) have tied the malware to APT10’s broader Operation Cloud Hopper campaign.
🔍 Detection Indicators
Known MD5 hashes include c1f6a0e3b7d4c8e9f2a5b6d7c9e1f3a4 (dropper variant) and 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d (core backdoor). Network indicators include HTTP POST requests to URLs ending with /images/ or /files/, using User‑Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value CuratorUpdater. A mutex named GlobalCuratorSyncMutex is created upon execution to prevent multiple instances.
☠️ Risk & Impact
Curator’s primary impact is long‑term intellectual property theft and strategic reconnaissance, particularly within the aerospace, defense, and technology industries. According to Unit 42 reports, victims have suffered exfiltration of program schematics, employee credentials, and internal network maps. Financial losses are difficult to quantify but include remediation costs, legal exposure, and competitive disadvantage due to stolen data.
🛡️ Mitigation
Defenders should deploy endpoint detection rules (e.g., Sysmon Event ID 1 for suspicious rundll32.exe child processes) and network‑based rules to block the described User‑Agent and DGA domains. Apply Microsoft patches for CVE‑2017‑0199 and CVE‑2017‑11882, and enable Office macro‑blocking policies. YARA rules matching the hardcoded XOR key and specific registry keys are available from the Unit 42 GitHub repository.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.