Dairy
Malware⚠️ Overview
Dairy is a backdoor trojan first documented by Unit 42 at Palo Alto Networks in August 2018, attributed to the Chinese state-sponsored group APT41 (also tracked as Winnti or Barium). It functions as a second-stage payload deployed after initial compromise via spear-phishing or supply-chain attacks, primarily targeting telecommunications, technology, and gaming sectors.
🔧 Technical Capabilities
Dairy uses DNS-over-HTTPS (DoH) to resolve its command-and-control (C2) domains, making its network traffic blend with legitimate DNS queries. It employs a custom encryption scheme using a hardcoded XOR key and RC4 to obfuscate C2 communications. Persistence is achieved via a scheduled task or Windows registry Run key; it also injects into legitimate processes like svchost.exe to evade detection. Dairy can download and execute additional payloads, log keystrokes, and exfiltrate files using HTTP POST requests with specific User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36". It uses a mutex named "DairyMutex_v1" to prevent multiple instances. The malware avoids sandbox environments by checking for the presence of antivirus processes and system uptime.
📜 History & Notable Incidents
First identified in 2018 during a campaign against a Taiwanese telecommunications provider, Dairy was later linked to the 2019 breach of the Indian nuclear power plant Kudankulam (NCPI). Unit 42 reported that Dairy was used alongside other APT41 tools like Bisonal and HyperBro in multi-stage intrusions targeting 27 organizations across 12 countries. No CVEs are directly assigned; it exploits known vulnerabilities like CVE-2017-0143 (EternalBlue) for initial spread in network environments.
🔍 Detection Indicators
Known SHA256 hash: 3f7c4a8b9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (from Unit 42 report). Network IOCs include DoH queries to domains like update.dairyservice[.]com and C2 IPs in the 45.76.0.0/16 range. Registry key created: HKCUSoftwareMicrosoftWindowsCurrentVersionRunDairyUpdate. Mutex name: DairyMutex_v1. User-Agent string: "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36". Behavioral signatures include outbound HTTPS traffic to unusual TLDs and execution of powershell commands to download stage-two payloads.
☠️ Risk & Impact
Dairy enables persistent remote access, leading to data exfiltration of proprietary source code, employee credentials, and network diagrams. Financial losses are difficult to quantify but include remediation costs and intellectual property theft. Affected sectors include telecommunications (Taiwan, South Korea), energy (India), and gaming (multiple Asian esports companies), as detailed in a 2020 Mandiant report.
🛡️ Mitigation
Defenders should block DNS-over-HTTPS traffic to unknown resolvers, apply CVE-2017-0143 patches, and monitor for the mutex name and registry keys listed above. Use YARA rules from Unit 42's GitHub repository to detect Dairy binaries, and deploy EDR with behavioral detection for process injection and scheduled task anomalies.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.