DropboxC2C is a remote access trojan (RAT) and backdoor that leverages the legitimate Dropbox API for command-and-control (C2) communication, first publicly documented in June 2018 by the Cisco Talos threat intelligence team. The malware is attributed to the Chinese-state-sponsored threat group APT10 (also tracked as Stone Panda, Red Apollo, or MENSA)
DropboxC2C uses the Dropbox cloud storage service as its C2 channel, sending encrypted commands and exfiltrated data via HTTP requests to the Dropbox API (api.dropboxapi.com). It employs a custom AES encryption scheme for communication obfuscation and stores configuration in the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. The malware propagates through spear-phishing emails containing malicious Microsoft Office documents (CVE-2017-11882 exploited) and lateral movement using PsExec or WMI. It evades detection by mimicking legitimate Dropbox traffic, using dynamically generated API tokens, and employing process hollowing to inject into svchost.exe or explorer.exe. DropboxC2C also periodically checks for updates by reading a special file hosted on Dropbox, allowing operators to replace the payload without direct network contact.
First observed targeting Japanese aerospace and defense organizations in 2018, DropboxC2C was part of a broader APT10 campaign codenamed Operation Cloud Hopper (reported by PwC in 2017). No specific CVEs are directly associated with DropboxC2C itself, but it commonly exploits CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) for initial access. Law enforcement actions include the indictment of two Chinese hackers by the U.S. Department of Justice in 2019 for APT10 activities, though DropboxC2C was not explicitly named in the indictment.
Known file hashes include SHA256: 3f5f8c9b1e2a4d6c7f0e9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8 (from Talos report). Behavioral signatures include persistent HTTPS traffic to api.dropboxapi.com with User-Agent strings like Dropbox-API-Client/1.0 or custom variations. Registry artifacts include the Run key value DropboxUpdate containing a reference to %APPDATA%dropboxc2.exe or similar.
DropboxC2C enables full remote control, keylogging, file exfiltration, and deployment of additional payloads such as the PlugX RAT. The malware has been linked to the theft of intellectual property from aerospace, defense, and manufacturing sectors in Japan, the United States, and Europe, with financial losses estimated in the hundreds of millions of dollars according to the 2020 DoJ indictment.
Defenders should block outbound traffic to unapproved cloud storage APIs, enforce application whitelisting, and deploy endpoint detection rules (e.g., Sigma rule ID posh_ps_dropbox_c2). Apply Microsoft patches for CVE-2017-11882 and use network monitoring tools to detect anomalous Dropbox API calls with unusual file sizes or frequencies.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.