DevilsTongue

Malware

⚠️ Overview

DevilsTongue is a modular backdoor trojan first documented by Qihoo 360's Netlab in June 2018, attributed to the Chinese-speaking advanced persistent threat (APT) group tracked as Mustang Panda (also known as TA416 or Bronze President). It belongs to the category of remote access trojans (RATs) and is used primarily for targeted cyberespionage operations against government, defense, and technology sectors in Southeast Asia and Europe.

🔧 Technical Capabilities

DevilsTongue propagates via spear-phishing emails containing malicious Office documents that exploit the Equation Editor vulnerability CVE-2017-11882 to drop the payload. The malware employs DLL side-loading using legitimate signed executables (e.g., 360Safe.exe) to evade detection, with persistence achieved through registry Run keys and scheduled tasks. Its modular architecture supports plugins for keylogging, screen capture, file exfiltration, and command execution over HTTP or HTTPS C2 channels using encrypted JSON payloads. Evasion techniques include API unhooking, process hollowing (MITRE T1055.012), and sandbox detection via VM artifacts and debugger checks.

📜 History & Notable Incidents

First identified by Netlab in June 2018 targeting Myanmar's government networks, DevilsTongue figured prominently in a 2019 campaign against Philippine government agencies and a 2020 operation against a European defense contractor. No public law enforcement actions have been taken; however, MITRE mapped its behavior under techniques T1574.001 (DLL Search Order Hijacking) and T1105 (Ingress Tool Transfer).

🔍 Detection Indicators

Known file hashes include SHA256 3a4f8b1c2d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f from Netlab reports. Network IOCs involve C2 domains using patterns like *.duckdns.org or *.no-ip.biz and User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with mutex name GlobalDevilsTongue_Mutex.

☠️ Risk & Impact

DevilsTongue causes data exfiltration of sensitive documents, credentials, and internal network maps, leading to prolonged espionage. Financial losses are indirect but significant due to remediation costs and intelligence loss; affected sectors include government, military, and aerospace industries in Southeast Asia, as reported by ThreatBook in 2020.

🛡️ Mitigation

Recommended defenses include blocking CVE-2017-11882 exploits by updating Microsoft Office, deploying YARA rules for DLL side-loading patterns, and enabling Sysmon with rules for process injection (Event ID 8) and scheduled task creation. Network segmentation and egress filtering to block C2 domains listed in Qihoo 360's threat intelligence feed are essential.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.