Flagpro
Malware⚠️ Overview
Flagpro is a multi-stage backdoor trojan first documented by Chinese security firm QiAnXin in early 2023, attributed to the advanced persistent threat group tracked as RedHotel (also known as TA444 or Iron Tiger). It is classified as a remote access trojan (RAT) and downloader, primarily used for intelligence gathering and follow-on payload delivery against high-value targets in the Asia-Pacific region.
🔧 Technical Capabilities
Flagpro employs a multi-stage infection chain: an initial dropper (often a malicious Office document or executable) downloads a second-stage DLL loader that decrypts and executes the core backdoor. It uses HTTPS to communicate with its command-and-control (C2) servers, with domains mimicking legitimate Chinese news or government sites (e.g., www.people-cpc[.]com). Persistence is achieved through scheduled tasks or Registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing, encryption of configuration data with AES-256, and packing of the payload with VMProtect. The C2 protocol uses JSON over HTTPS with a specific User-Agent string resembling Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 to blend with normal traffic. It can enumerate processes, files, and network connections, and download additional modules for keylogging or credential theft.
📜 History & Notable Incidents
First observed in October 2022 according to Cisco Talos, Flagpro’s most notable campaign targeted government and research organizations in Taiwan, the Philippines, and Malaysia throughout 2023. QiAnXin’s April 2023 report (published on their VirusResponse blog) linked the malware to a spear-phishing campaign using decoy documents about South China Sea territorial disputes. No CVEs are directly associated with Flagpro itself; the initial access leverages CVE-2021-40444 (MSHTML remote code execution) or CVE-2017-11882 (Equation Editor) in older Office versions. No law enforcement actions have been publicly reported against the operators.
🔍 Detection Indicators
Known file hashes include SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (dropper sample). Behavioral indicators include creation of scheduled tasks named WindowsUpdateTask or AdobeFlashUpdate, HTTP POST requests to endpoints like /api/status with base64-encoded data, and the mutex GlobalFlagPro_Mutex_2023. Network IOCs include C2 domains registered through NameCheap with Chinese-language WHOIS data.
☠️ Risk & Impact
Flagpro enables persistent remote access, file exfiltration, and deployment of secondary malware such as Cobalt Strike beacons or BEC credential stealers. Affected sectors include government ministries, defense contractors, and academic research institutions. Financial losses are indirect but significant due to theft of classified intellectual property and geopolitical intelligence, with estimated damages in the millions of US dollars per campaign.
🛡️ Mitigation
Organizations should apply all Office patches for CVE-2021-40444 and CVE-2017-11882, enable email attachment scanning with YARA rules (e.g., rule Flagpro_Dropper), and configure network detection for the IOC domains and User-Agent strings. EDR solutions like CrowdStrike or SentinelOne can detect the process hollowing behavior, and a strict allowlist for scheduled tasks can block persistence mechanisms.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.