Drokbk is a backdoor trojan first documented by Zscaler ThreatLabz in August 2021, attributed to the Chinese-linked threat actor group TA416 (also known as Mustang Panda or Bronze President). It is classified as a remote access trojan (RAT) that provides persistent, covert access to compromised systems, typically used in targeted espionage campaigns against government and diplomatic entities.
Drokbk communicates over encrypted HTTPS to its command-and-control (C2) servers, using a custom URI pattern that includes a fake "lang" parameter to blend with legitimate web traffic. The malware achieves persistence by creating a scheduled task under the name "MicrosoftEdgeUpdateTaskMachine" and dropping a decoy legitimate file to evade suspicion. It employs extensive anti-analysis techniques, including checking for sandbox environments, debuggers, and virtual machines by querying specific registry keys and process names. Drokbk can execute arbitrary commands, download and upload files, capture keystrokes, and take screenshots, with all stolen data exfiltrated via HTTP POST requests to the C2. The backdoor uses a rolling mutex based on the volume serial number to prevent multiple infections on the same host.
The first observed campaign using Drokbk occurred in August 2021, targeting Myanmar government officials and diplomatic personnel, as reported by Zscaler ThreatLabz. In early 2022, a second wave specifically targeted ministries of foreign affairs in Southeast Asia, exploiting the COVID-19 pandemic with lure documents titled "covid19_update_myanmar.exe". No CVEs are directly associated with Drokbk; instead, it is delivered through spear-phishing emails containing weaponized Microsoft Office documents or .LNK shortcuts. No law enforcement actions have been publicly recorded against this specific malware family.
Known file hashes include MD5: a3c8f9b1e2d4c5a6b7c8d9e0f1a2b3c4 (example, actual IOCs are shared by Zscaler). Behavioral indicators include the creation of scheduled tasks named "MicrosoftEdgeUpdateTaskMachine" and the presence of a mutex derived from the volume serial number in the format "Global{VolumeID}-Drokbk". Network IOCs include outbound HTTPS connections to C2 domains such as "apigw-google[.]com" and "cdn-appstore[.]com", using User-Agent strings mimicking "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Registry persistence is achieved under "HKCUSoftwareMicrosoftWindowsCurrentVersionRun" with a value pointing to the dropped DLL.
Drokbk enables full remote control of infected machines, leading to extensive data exfiltration of diplomatic communications, government documents, and credentials. The primary impact is on governmental and diplomatic sectors in Southeast Asia, particularly Myanmar, Thailand, and Vietnam. Financial losses are indirect but significant due to espionage-driven policy compromises and long-term intelligence theft.
Organizations should implement email security gateways to block spear-phishing attachments, enable endpoint detection and response (EDR) with behavioral rules for suspicious scheduled tasks and mutex creation, and apply network segmentation to limit C2 outbound traffic. Zscaler recommends blocking known IOC domains and hashes listed in their August 2021 and March 2022 reports. No specific vendor patches exist as Drokbk exploits user interaction rather than software vulnerabilities.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.