Drokbk
Malware⚠️ Overview
Drokbk is a backdoor trojan first documented by Zscaler ThreatLabz in August 2021, attributed to the Chinese-linked threat actor group TA416 (also known as Mustang Panda or Bronze President). It is classified as a remote access trojan (RAT) that provides persistent, covert access to compromised systems, typically used in targeted espionage campaigns against government and diplomatic entities.
🔧 Technical Capabilities
Drokbk communicates over encrypted HTTPS to its command-and-control (C2) servers, using a custom URI pattern that includes a fake "lang" parameter to blend with legitimate web traffic. The malware achieves persistence by creating a scheduled task under the name "MicrosoftEdgeUpdateTaskMachine" and dropping a decoy legitimate file to evade suspicion. It employs extensive anti-analysis techniques, including checking for sandbox environments, debuggers, and virtual machines by querying specific registry keys and process names. Drokbk can execute arbitrary commands, download and upload files, capture keystrokes, and take screenshots, with all stolen data exfiltrated via HTTP POST requests to the C2. The backdoor uses a rolling mutex based on the volume serial number to prevent multiple infections on the same host.
📜 History & Notable Incidents
The first observed campaign using Drokbk occurred in August 2021, targeting Myanmar government officials and diplomatic personnel, as reported by Zscaler ThreatLabz. In early 2022, a second wave specifically targeted ministries of foreign affairs in Southeast Asia, exploiting the COVID-19 pandemic with lure documents titled "covid19_update_myanmar.exe". No CVEs are directly associated with Drokbk; instead, it is delivered through spear-phishing emails containing weaponized Microsoft Office documents or .LNK shortcuts. No law enforcement actions have been publicly recorded against this specific malware family.
🔍 Detection Indicators
Known file hashes include MD5: a3c8f9b1e2d4c5a6b7c8d9e0f1a2b3c4 (example, actual IOCs are shared by Zscaler). Behavioral indicators include the creation of scheduled tasks named "MicrosoftEdgeUpdateTaskMachine" and the presence of a mutex derived from the volume serial number in the format "Global{VolumeID}-Drokbk". Network IOCs include outbound HTTPS connections to C2 domains such as "apigw-google[.]com" and "cdn-appstore[.]com", using User-Agent strings mimicking "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Registry persistence is achieved under "HKCUSoftwareMicrosoftWindowsCurrentVersionRun" with a value pointing to the dropped DLL.
☠️ Risk & Impact
Drokbk enables full remote control of infected machines, leading to extensive data exfiltration of diplomatic communications, government documents, and credentials. The primary impact is on governmental and diplomatic sectors in Southeast Asia, particularly Myanmar, Thailand, and Vietnam. Financial losses are indirect but significant due to espionage-driven policy compromises and long-term intelligence theft.
🛡️ Mitigation
Organizations should implement email security gateways to block spear-phishing attachments, enable endpoint detection and response (EDR) with behavioral rules for suspicious scheduled tasks and mutex creation, and apply network segmentation to limit C2 outbound traffic. Zscaler recommends blocking known IOC domains and hashes listed in their August 2021 and March 2022 reports. No specific vendor patches exist as Drokbk exploits user interaction rather than software vulnerabilities.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.