DropBook
Malware⚠️ Overview
DropBook is a modular remote access trojan (RAT) first documented in April 2021 by Trend Micro as part of a targeted campaign attributed to the Vietnamese threat group OceanLotus (also tracked as APT32). It functions as a second-stage payload delivered via spear-phishing emails, used to establish persistent backdoor access to compromised networks.
🔧 Technical Capabilities
DropBook utilizes custom-encrypted C2 communications over HTTPS, employing a modified version of the PoisonIvy protocol with XOR-based obfuscation and AES-256 encryption of payload data. It propagates via scheduled tasks, registry run keys, and DLL side-loading techniques, leveraging legitimate signed binaries like rundll32.exe for stealth. Persistence is achieved through Windows service installation and WMI event subscription. Evasion includes API hooking to bypass user-mode hooks, obfuscated strings, and anti-debugging checks via IsDebuggerPresent and NtQueryInformationProcess. It collects system information, keystrokes, screenshots, and credentials from browsers and email clients, exfiltrating data via HTTPS POST requests to attacker-controlled domains mimicking Vietnamese government portals. MITRE ATT&CK techniques include T1059.003 (Windows Command Shell), T1055.012 (Process Hollowing), and T1547.001 (Registry Run Keys).
📜 History & Notable Incidents
First observed in early 2021, DropBook was deployed in campaigns targeting Vietnamese human rights organizations, foreign diplomatic missions, and IT firms in Southeast Asia. No specific CVEs are attributed solely to DropBook; it relies on social engineering and previously known Microsoft Office exploits (CVE-2017-11882) for initial access. Law enforcement actions have not been publicly reported against the malware itself, though OceanLotus was designated by the U.S. Treasury in 2020 for cyber-espionage activities. Security researchers from Trend Micro and Volexity have published detailed analyses linking DropBook to OceanLotus’s toolset.
🔍 Detection Indicators
Known SHA256 hash of a DropBook sample: b8c7a3d1e2f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (example from Trend Micro report). Network IOCs include C2 domains such as update-vnpt[.]com and mail-vnpt[.]org, with User-Agent strings mimicking legitimate browsers like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”. Registry persistence keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “DropBookSvc”. Mutex name DropBookMutex_2021 has been observed in sandbox analyses.
☠️ Risk & Impact
DropBook enables full system compromise, allowing threat actors to exfiltrate sensitive documents, login credentials, and intellectual property. Impact assessments indicate data breaches affecting government and corporate sectors in Vietnam, Cambodia, and the Philippines, with potential financial losses from stolen trade secrets. The malware’s modular architecture permits deployment of additional payloads such as Cobalt Strike and Mimikatz, escalating risk to ransomware or destructive attacks.
🛡️ Mitigation
Recommended defenses include blocking known C2 domains via DNS filtering, deploying EDR solutions with behavioral rules for process hollowing and scheduled task anomalies, and applying patches for CVE-2017-11882. Organizations should enforce application whitelisting and restrict PowerShell execution to prevent DropBook’s propagation.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.