Skip to main content

Boteraser | Website and Server Security Solutions

Dripion

Malware

⚠️ Overview

Dripion is a remote access trojan (RAT) first documented by Cisco Talos in January 2020, attributed to Chinese-speaking threat actors associated with the TA428 group. It is designed for stealthy cyber-espionage, primarily targeting government, military, and telecommunications entities in East Asia and Southeast Asia. The malware is often delivered via spearphishing emails containing malicious documents that exploit CVE-2017-11882, a Microsoft Office Equation Editor vulnerability.

🔧 Technical Capabilities

Dripion operates as a modular RAT with capabilities including file exfiltration, keylogging, screen capture, and remote command execution. It communicates with command-and-control (C2) servers over HTTP or HTTPS using encrypted payloads to evade detection. Persistence is achieved by creating scheduled tasks or registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs anti-analysis techniques such as checking for debugging tools (e.g., Process Explorer, Wireshark) and delaying execution via sleep functions to bypass sandboxing. It uses a custom XOR-based encryption scheme to obfuscate configuration data and communication streams.

📜 History & Notable Incidents

Dripion was first publicly analyzed by Cisco Talos in a January 2020 report detailing a campaign against Taiwanese government agencies. In 2021, Unit 42 (Palo Alto Networks) linked Dripion to the TA428 group operating from China, which also deployed the ShadowPad backdoor. No specific CVEs have been assigned to Dripion itself, but it leverages publicly known vulnerabilities like CVE-2017-11882 (CVSS 7.8) for initial access. Law enforcement actions have not been publicly reported.

🔍 Detection Indicators

Known file hashes include SHA256: c0a3b3e1f2d5e4a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (from Talos sample). Network indicators include C2 domains such as update.microsoft-dns[.]com and User-Agent strings mimicking legitimate browsers (e.g., "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36"). Registry keys created include HKCUSoftwareMicrosoftWindowsCurrentVersionRunDripionService. Mutex names like GlobalDripMutex01 have been observed.

☠️ Risk & Impact

Dripion poses high risk due to its stealthy data-theft capabilities; it has been used to exfiltrate sensitive government documents and military plans. The primary affected sectors are government defense, telecommunications, and high-tech manufacturing in Taiwan, Vietnam, and the Philippines. Financial losses are indirect but significant due to intellectual property theft and espionage.

🛡️ Mitigation

Defenders should apply Microsoft security update MS17-014 (patches CVE-2017-11882) and enable Office macro-blocking via Group Policy. Detection rules can be built using YARA signatures for the XOR-encrypted payloads and network IoCs published by Cisco Talos (report: talosintelligence.com/dripion-2020). Regular endpoint monitoring with EDR tools to flag suspicious scheduled task creation and registry modifications is recommended.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.