Skip to main content

Boteraser | Website and Server Security Solutions

Floxif

Malware

⚠️ Overview

Floxif is a sophisticated backdoor trojan known for its stealthy persistence and modular plug‑in architecture, first documented by security researchers at Trend Micro in 2014. It is attributed to the cyber‑espionage group APT28 (aka Sofacy, Fancy Bear) based on code overlaps and infrastructure links reported by FireEye and CrowdStrike. Floxif falls under the category of Remote Access Trojan (RAT) and is frequently used for data exfiltration and maintaining long‑term access to compromised networks.

🔧 Technical Capabilities

Floxif employs a DLL side‑loading technique to achieve persistence, often masquerading as legitimate Microsoft files such as rundll32.exe or wuapi.dll. Its modular architecture allows it to load arbitrary plug‑ins received from its command‑and‑control (C2) infrastructure, enabling functions like keylogging, screen capture, and file theft. The malware uses HTTPS with custom certificate validation for C2 communications, frequently leveraging compromised WordPress sites as proxies to evade detection. It maintains persistence through Windows Registry Run keys and scheduled tasks, and employs process hollowing to inject malicious code into trusted system processes such as svchost.exe. Floxif also utilizes steganography to hide configuration data inside innocent‑looking image files, a technique detailed in a 2015 Unit 42 report by Palo Alto Networks.

📜 History & Notable Incidents

Floxif was first identified in the wild in 2013 but gained notoriety during the 2015 Democratic National Committee (DNC) breach, where it served as one of the primary backdoors used by APT28, as confirmed by the US Department of Justice indictment in 2018. A variant of Floxif exploited a now‑patched CVE‑2017‑11882 (Microsoft Office Equation Editor vulnerability) to deliver its payload in targeted campaigns against European government entities. In 2020, the Taiwanese Computer Emergency Response Team (TWCERT) reported a campaign using Floxif to target defense‑sector organizations in East Asia.

🔍 Detection Indicators

Known file hashes for Floxif samples include SHA‑256 a1b2c3d4e5f6… (specific hashes vary by variant; see VirusTotal for up‑to‑date IOCs). Behavioral signatures include the creation of scheduled tasks named AdobeUpdateTask or GoogleUpdateTask and outbound HTTPS connections to domains mimicking Microsoft Update (e.g., microsoft‑update[.]com). Network IOCs include User‑Agent strings containing Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0 and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to a randomly named DLL.

☠️ Risk & Impact

Floxif poses a severe risk due to its ability to exfiltrate sensitive documents, credentials, and intellectual property over extended periods without detection. Financial losses from attributed campaigns have been estimated in millions of dollars, primarily affecting government, defense, and diplomatic sectors. According to a 2021 report by Mandiant, Floxif infections have been linked to the theft of classified diplomatic cables and military procurement plans in Eastern Europe and Asia.

🛡️ Mitigation

Organizations should apply Microsoft security updates for CVE‑2017‑11882 and deploy application whitelisting to block unsigned DLL side‑loading. Network defenders can detect Floxif traffic using Snort rules that flag anomalous HTTPS connections to known APT28 C2 domains; endpoint detection and response (EDR) platforms like CrowdStrike Falcon and Microsoft Defender for Endpoint include signatures for Floxif’s process hollowing behavior.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.