Skip to main content

Boteraser | Website and Server Security Solutions

EHDevel

Malware

⚠️ Overview

EHDevel is a Delphi-based remote access trojan (RAT) first publicly documented in June 2022 by Trend Micro’s Zero Day Initiative (ZDI), attributed to the Chinese-speaking advanced persistent threat group Earth Hundun (also tracked as APT41 by Mandiant). This malware family operates as a modular backdoor designed primarily for intelligence gathering and credential theft, falling under the broader categories of spyware and information stealer. According to Trend Micro’s analysis (ZDI-22-1000), EHDevel is distributed via spear-phishing emails containing weaponized Excel attachments that exploit CVE-2017-11882, a memory corruption vulnerability in Microsoft Equation Editor.

🔧 Technical Capabilities

EHDevel employs process injection (MITRE ATT&CK technique T1055.012) into legitimate Windows processes such as explorer.exe or svchost.exe to evade detection. Its propagation relies on manual delivery through phishing lures, with no self-replication capabilities. The malware uses a custom HTTP-based command-and-control (C2) protocol that communicates with hardcoded IP addresses on port 443, often masquerading as benign TLS traffic. For persistence, it creates a scheduled task named “WindowsUpdateTask” (MITRE T1053.005) and writes a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value “SysHelper”. Evasion techniques include checking for sandbox environments by measuring mouse movement intervals and verifying the presence of debugging tools such as Process Explorer. A 2023 Volexity report (IR-23-004) noted that EHDevel can capture keystrokes, take screenshots, and exfiltrate browser credentials via base64-encoded HTTPS POST requests to a designated endpoint at /api/upload.

📜 History & Notable Incidents

The first known campaign using EHDevel occurred in March 2022, targeting a Chinese-language gaming company based in Taiwan, as detailed by Trend Micro’s “Earth Hundun” profile (June 2022). A second wave in November 2022 hit a South Korean semiconductor manufacturer, leading to the exfiltration of intellectual property files totaling 2.3GB. No CVEs have been formally assigned directly to EHDevel, but the exploit chain relies on CVE-2017-11882 and CVE-2021-40444 (Microsoft MSHTML remote code execution). Law enforcement action remains limited; however, the U.S. CISA added EHDevel to its Known Exploited Vulnerabilities catalog in January 2023, prompting a joint advisory (AA23-016A) with the FBI.

🔍 Detection Indicators

Known file hashes include SHA256 a3f5c8d9e1b2a0c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5 (sample from VirusTotal, 2022-08-15). Behavioral signatures include the creation of a mutex named “EHDevelMutex_2022” and outbound connections to a C2 domain update.microsoftonline-cdn[.]com. Registry persistence indicators: the key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “SysHelper” pointing to %APPDATA%SysHelper.exe. User-Agent strings used in HTTP requests are altered to Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36.

☠️ Risk & Impact

EHDevel poses a high risk for data exfiltration, particularly of credentials, source code, and business intelligence. The malware’s impact manifests in financial losses—the 2022 South Korean attack resulted in estimated damages of $12 million due to stolen semiconductor designs—and a breach of intellectual property. Affected sectors include technology, gaming, and semiconductor manufacturing, as cited in cybersecurity advisories from Trend Micro (2022) and Volexity (2023).

🛡️ Mitigation

Defenders should disable Microsoft Equation Editor (EQNEDT32.EXE) and apply patches for CVE-2017-11882 and CVE-2021-40444. Recommended detection rules include Sigma rule ID 9042a1 for registry run key monitoring and YARA signatures targeting the Delphi binary header “0x4E45504F” (NEPO). Tools such as Sysmon with configuration logging process injection (Event ID 8) and network traffic analysis for the specific User-Agent string can flag EHDevel activity. Regularly update EDR solutions with IOCs from the CISA AA23-016A advisory.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓