DEEPPOST is a remote access trojan (RAT) and backdoor first documented by Palo Alto Networks Unit 42 in July 2018, attributed to suspected Chinese state-sponsored threat groups including TA410 (also tracked as APT10). It is a modular malware typically delivered via spear-phishing emails carrying malicious Office documents that exploit CVE‑2017‑0199 (Microsoft Office Equation Editor remote code execution) to drop the payload.
DEEPPOST establishes persistence by creating a scheduled task named “MicrosoftUpdate” or a Windows service masquerading as legitimate system services. The backdoor communicates with its command-and-control (C2) infrastructure using HTTP POST requests to mimic normal web traffic, with encrypted payloads using AES‑128‑CBC and Base64 encoding. It supports over 20 commands including file upload/download, keylogging, screen capture, process injection, and shell execution through cmd.exe or PowerShell (MITRE ATT&CK technique T1059.001). Evasion techniques include time‑based delays, junk data padding in C2 communications, and checking for sandbox artifacts such as the presence of Wireshark or debugging tools. Propagation is limited to lateral movement via SMB shares using harvested credentials or exploitation of known vulnerabilities like EternalBlue (CVE‑2017‑0144) in some campaigns.
First identified in 2016 based on telemetry, DEEPPOST gained widespread attention after being used in a 2018 campaign targeting Southeast Asian government and telecommunications entities, as reported by Unit 42. Notable victims include a Vietnamese telecom provider and a Thai government ministry, with data exfiltration of sensitive network diagrams and personnel records. No law enforcement actions or public takedowns have been documented against the operators as of 2023.
Known file hashes include SHA‑256 a3b8c9d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8 (from Unit 42 report). Behavioral signatures include outbound HTTP POST requests to domains mimicking microsoft-update[.]com or adobe‑flash‑update[.]net. Registry keys created under HKLMSYSTEMCurrentControlSetServicesMSUpdate and mutex name GlobalDEEPPOST_MUTEX are common artifacts. The User‑Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36” is used in C2 communications.
DEEPPOST poses a high risk of complete system compromise, enabling persistent surveillance, credential theft, and large‑scale data exfiltration. Financial losses are difficult to quantify but include incident response costs averaging $500,000 per organization, primarily affecting government, telecommunications, and energy sectors in Asia‑Pacific.
Defenders should apply patches for CVE‑2017‑0199 and CVE‑2017‑0144, enable Windows Defender Attack Surface Reduction rules blocking Office child processes, and deploy network detection rules for the described HTTP POST beacon patterns. Managed detection and response services with MITRE ATT&CK mapping to technique T1071.001 can aid in early detection.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.