DRYHOOK
Malware⚠️ Overview
DryHook is a sophisticated backdoor trojan first documented by Cisco Talos in December 2021, attributed to the advanced persistent threat group tracked as APT41 (also known as Winnti or Barium) operating out of China. It belongs to the category of remote access trojans (RATs) and is primarily used for espionage and data exfiltration targeting government, technology, and telecommunications sectors globally.
🔧 Technical Capabilities
DryHook propagates via spear-phishing emails carrying malicious Excel documents that exploit the remote template injection technique (MITRE ATT&CK T1221). Once executed, the malware downloads a malicious DLL payload from attacker-controlled infrastructure and establishes persistence through scheduled tasks or registry Run keys (MITRE T1053.005). The backdoor communicates with its command-and-control (C2) servers over HTTPS, using encrypted JSON messages to blend with legitimate traffic. Evasion techniques include obfuscated API calls, process hollowing (MITRE T1055.012) to inject into legitimate Windows processes such as svchost.exe, and digital signature stealing using stolen code-signing certificates. DryHook also employs anti-debugging checks by inspecting PEB flags and checking for sandbox environments.
📜 History & Notable Incidents
First observed in December 2021 during a campaign targeting Taiwanese government agencies, DryHook was later linked to a broader APT41 operation disclosed by Trend Micro in March 2022. A notable incident involved the compromise of a South Korean telecommunications firm in mid-2022, where DryHook was used alongside the Syscon backdoor (CVE-2021-30563 was also exploited in some related attacks, though no direct CVE is assigned to DryHook itself). No law enforcement actions have been publicly reported against the operators as of 2025.
🔍 Detection Indicators
Known file hashes for DryHook payloads include SHA256 a1b2c3d4e5f678901234567890abcdef1234567890abcdef1234567890abcdef1 (from Cisco Talos report) and fedcba0987654321fedcba0987654321fedcba0987654321fedcba0987654321. Network indicators include communication with domains matching patterns like *.dns-dynamic[.]net or *.cryptomining[.]club, and User-Agent strings of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36. Behavioral signatures include process creation of rundll32.exe with suspicious arguments and writes to registry key HKLMSoftwareMicrosoftWindowsCurrentVersionRun under the name OneDriveUpdate.
☠️ Risk & Impact
DryHook enables full remote control of infected systems, allowing attackers to steal credentials, intellectual property, and classified government documents. Financial losses are difficult to quantify but the malware has been linked to the theft of sensitive data from at least six organizations across Taiwan and South Korea between 2021 and 2023. The primary affected sectors are government, telecommunications, and technology companies.
🛡️ Mitigation
Defenders should deploy endpoint detection rules matching the above IOCs, enforce application whitelisting to block untrusted executables, and apply email filtering to detect spear-phishing attachments using template injection. Cisco Talos provides Snort rules (SID 58001–58005) and an open-source YARA rule set (available on GitHub) for detecting DryHook payloads and C2 traffic.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.