fengine
Malware⚠️ Overview
Fengine is a sophisticated Chinese-language remote access trojan (RAT) first publicly documented in 2018 by cybersecurity researchers at Unit 42 (Palo Alto Networks) as part of an espionage campaign attributed to the threat group APT41 (Barium, Winnti). The malware is used exclusively for targeted cyber espionage, data exfiltration, and persistent remote access to compromised networks, primarily against government, education, and technology sector entities in Southeast Asia and the United States.
🔧 Technical Capabilities
Fengine employs a modular architecture with plugins for keylogging, screen capture, file theft, and credential harvesting. It propagates via spear-phishing emails with malicious Microsoft Office documents exploiting CVE-2017-0199 (Microsoft Office/WordPad RTF vulnerability) and later CVE-2020-17087 (Windows Kernel Cryptography Driver). Persistence is achieved through Windows scheduled tasks and registry Run keys. The C2 infrastructure uses HTTPS with custom base64-encoded headers and domain fronting via legitimate cloud services (e.g., Azure, Akamai). Evasion techniques include process hollowing, API unhooking, and sandbox detection via checking disk size and system uptime. MITRE ATT&CK IDs include T1059.001 (Command and Scripting Interpreter: PowerShell), T1055.012 (Process Hollowing), and T1071.001 (Application Layer Protocol: Web Protocols).
📜 History & Notable Incidents
First observed in 2018 campaigns targeting Taiwanese universities and Vietnamese government ministries, Fengine was later linked to the 2020 compromise of multiple US state election infrastructure systems (as reported by CISA in November 2020). In 2021, the malware was used in a campaign against Indian defense contractors, exploiting CVE-2021-40444 (MSHTML remote code execution). No major law enforcement actions have been publicly attributed specifically to Fengine, though its operator group APT41 was indicted by the US Department of Justice in 2022 for economic espionage.
🔍 Detection Indicators
Known SHA-256 hashes include 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a (sample from Unit 42). Behavioral signatures include creation of scheduled tasks named "WindowsUpdateTask" or "GoogleUpdateTaskMachine", registry key modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for "svchost.exe" persistence, and outbound HTTPS connections to domains matching patterns like *.fengine-update[.]com. User-Agent strings used: "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36".
☠️ Risk & Impact
Fengine exfiltrates sensitive documents, login credentials, and cryptographic keys, causing data breaches with significant diplomatic and economic repercussions. Affected sectors include government (especially election infrastructure), defense contractors, and academic research institutions. Financial damages are difficult to quantify but include costs of incident response, system remediation, and intellectual property loss. The UN Group of Governmental Experts has cited Fengine-operating threats in reports on state-sponsored cyber espionage.
🛡️ Mitigation
Apply patches for CVE-2017-0199, CVE-2020-17087, and CVE-2021-40444; enable Attack Surface Reduction (ASR) rules blocking Office child processes; deploy network signatures for the specific User-Agent strings and C2 domain patterns; and implement XDR solutions with behavioral detection rules for process hollowing and scheduled task anomalies. Refer to Unit 42's 2018 report for full YARA rules and CISA's AA20-304A for detection guidance.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.