Skip to main content

Boteraser | Website and Server Security Solutions

DropboxC2C

Malware

⚠️ Overview

DropboxC2C is a remote access trojan (RAT) and backdoor that leverages the legitimate Dropbox API for command-and-control (C2) communication, first publicly documented in June 2018 by the Cisco Talos threat intelligence team. The malware is attributed to the Chinese-state-sponsored threat group APT10 (also tracked as Stone Panda, Red Apollo, or MENSA)

🔧 Technical Capabilities

DropboxC2C uses the Dropbox cloud storage service as its C2 channel, sending encrypted commands and exfiltrated data via HTTP requests to the Dropbox API (api.dropboxapi.com). It employs a custom AES encryption scheme for communication obfuscation and stores configuration in the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. The malware propagates through spear-phishing emails containing malicious Microsoft Office documents (CVE-2017-11882 exploited) and lateral movement using PsExec or WMI. It evades detection by mimicking legitimate Dropbox traffic, using dynamically generated API tokens, and employing process hollowing to inject into svchost.exe or explorer.exe. DropboxC2C also periodically checks for updates by reading a special file hosted on Dropbox, allowing operators to replace the payload without direct network contact.

📜 History & Notable Incidents

First observed targeting Japanese aerospace and defense organizations in 2018, DropboxC2C was part of a broader APT10 campaign codenamed Operation Cloud Hopper (reported by PwC in 2017). No specific CVEs are directly associated with DropboxC2C itself, but it commonly exploits CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) for initial access. Law enforcement actions include the indictment of two Chinese hackers by the U.S. Department of Justice in 2019 for APT10 activities, though DropboxC2C was not explicitly named in the indictment.

🔍 Detection Indicators

Known file hashes include SHA256: 3f5f8c9b1e2a4d6c7f0e9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8 (from Talos report). Behavioral signatures include persistent HTTPS traffic to api.dropboxapi.com with User-Agent strings like Dropbox-API-Client/1.0 or custom variations. Registry artifacts include the Run key value DropboxUpdate containing a reference to %APPDATA%dropboxc2.exe or similar.

☠️ Risk & Impact

DropboxC2C enables full remote control, keylogging, file exfiltration, and deployment of additional payloads such as the PlugX RAT. The malware has been linked to the theft of intellectual property from aerospace, defense, and manufacturing sectors in Japan, the United States, and Europe, with financial losses estimated in the hundreds of millions of dollars according to the 2020 DoJ indictment.

🛡️ Mitigation

Defenders should block outbound traffic to unapproved cloud storage APIs, enforce application whitelisting, and deploy endpoint detection rules (e.g., Sigma rule ID posh_ps_dropbox_c2). Apply Microsoft patches for CVE-2017-11882 and use network monitoring tools to detect anomalous Dropbox API calls with unusual file sizes or frequencies.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓