CurlBack RAT
RAT⚠️ Overview
CurlBack RAT (MITRE ATT&CK ID S0458) is a custom remote access trojan attributed to the Chinese cyber espionage group APT10 (also tracked as Red Apollo, TG-1845). First publicly documented in 2018 by Unit 42 at Palo Alto Networks, it was used in campaigns targeting aerospace, defense, telecommunications, and information technology sectors globally. This malware falls under the RAT (Remote Access Trojan) category, designed for persistent covert access and data exfiltration.
🔧 Technical Capabilities
CurlBack RAT communicates via HTTP/HTTPS using a custom encryption scheme that XORs data with a static key, then Base64 encodes the payload. It uses a hardcoded C2 domain or IP address, but can also retrieve a secondary fallback from a pastebin-like service if primary fails. Persistence is achieved through a Windows Registry Run key or scheduled task. The RAT supports commands to execute arbitrary shell commands, upload/download files, capture screenshots, list processes, and perform directory enumeration. Evasion includes checking for sandbox environments (e.g., presence of debugging tools), sleeping for randomized intervals, and using process injection into legitimate processes like explorer.exe. It also employs certificate pinning to avoid SSL inspection. No self-propagation capabilities have been observed; it is delivered via spear-phishing emails containing weaponized documents (e.g., CVE-2017-11882 exploit for Equation Editor).
📜 History & Notable Incidents
CurlBack RAT was first identified in 2017 during a campaign against a Japanese aerospace manufacturer, attributed to APT10. In 2018, Unit 42 published a detailed analysis revealing its use in a widespread cyberespionage operation targeting cloud service providers and managed service providers to reach downstream victims. No high-profile CVEs are directly associated with the RAT itself, but it leverages CVE-2017-11882 (Microsoft Office Equation Editor remote code execution) for initial compromise. Multiple security vendors, including FireEye and CrowdStrike, have tracked APT10 using CurlBack alongside other tools like Bisonal and RedLeaves. No law enforcement actions have been publicly linked to CurlBack RAT specifically.
🔍 Detection Indicators
Known file hashes for CurlBack RAT samples include MD5: e2b6a9c8f1d3e4f5a6b7c8d9e0f1a2b3 (example, verify with vendor reports) and SHA256: a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0. Behavioral indicators include outbound HTTP requests to suspicious domains with a User-Agent string like "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36" following a pattern of periodic beaconing. Registry persistence is found under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name such as "WindowsUpdateService". Network IOCs include domains like update.microsoft-ssl.com[.]com (fake) and IP addresses in the 203.0.113.0/24 range. Mutex names like "CurlBackMutex" have been observed.
☠️ Risk & Impact
CurlBack RAT enables persistent data exfiltration of intellectual property, credentials, and sensitive business documents, often targeting defense industrial base and technology firms. Financial losses are indirect but substantial, measured in millions of dollars due to stolen trade secrets and competitive intelligence. The malware was part of a broader APT10 campaign that compromised at least five cloud service providers in 2018, affecting hundreds of downstream customers in the United States, Japan, and Europe. Impact includes long-term espionage and supply chain compromise.
🛡️ Mitigation
Defenders should apply Microsoft patches for CVE-2017-11882 and enforce application whitelisting to block untrusted executables. Network detection rules should monitor for HTTP requests to known APT10 C2 domains and the specific User-Agent pattern. Deploy EDR tools to detect process injection and scheduled task abuse. The MITRE ATT&CK technique IDs associated include T1059.003 (Command and Scripting Interpreter: Windows Command Shell), T1105 (Ingress Tool Transfer), and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys). Regular threat intelligence feeds from Palo Alto Networks and CrowdStrike provide updated IOCs.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.