FlyStudio
Malware⚠️ Overview
FlyStudio is a Chinese-language remote access trojan (RAT) first documented publicly in 2012 by the malware research community, with attribution to the threat group tracked as APT10 (also known as Stone Panda or MenuPass). According to a 2019 report by the National Cyber Security Centre (NCSC) of the United Kingdom, FlyStudio has been used in targeted espionage campaigns against defense, aerospace, and technology sectors worldwide.
🔧 Technical Capabilities
FlyStudio propagates via spear-phishing emails containing malicious Office documents with embedded PowerShell scripts, exploiting CVE-2017-11882 (Microsoft Equation Editor) and CVE-2018-0798 for initial execution. Once deployed, it establishes C2 communications over HTTP and HTTPS using a custom protocol with encrypted payloads, and maintains persistence through registry Run keys and scheduled tasks. The malware evades detection by employing process hollowing, encrypting strings with a custom XOR variant, and using DLL side-loading techniques to load its core payload from legitimate signed binaries. MITRE ATT&CK techniques used include T1059.001 (PowerShell), T1055.012 (Process Hollowing), and T1574.002 (DLL Side-Loading).
📜 History & Notable Incidents
First identified in 2012, FlyStudio was heavily deployed in the 2018 Operation Cloud Hopper campaign attributed to APT10, which compromised multiple managed service providers (MSPs) and their clients globally. In 2019, the NCSC report linked FlyStudio to intrusions into the UK Ministry of Defence and aerospace firms. No specific CVEs have been exclusively assigned to FlyStudio itself, but it exploits publicly known vulnerabilities listed above.
🔍 Detection Indicators
Behavioral signatures include outbound HTTP POST requests to IP addresses in China with User-Agent strings such as "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0)" and base64-encoded data in request bodies. Known mutex names include "FlyStudio_Mutex" (case-insensitive). Registry persistence appears under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a key named "FlyStudioSvc". No public SHA256 hashes for specific FlyStudio samples are widely documented; analysts rely on behavior-based detection rules.
☠️ Risk & Impact
FlyStudio enables full remote control of infected hosts, including file exfiltration, keystroke logging, screen capture, and credential theft. According to the 2019 NCSC advisory, the malware targeted military and manufacturing sectors in the UK, US, Japan, and South Korea, with financial impacts exceeding hundreds of millions of dollars due to intellectual property theft and operational disruption.
🛡️ Mitigation
Defenders should apply patches for CVE-2017-11882 and CVE-2018-0798, deploy email filtering to block spear-phishing attachments with embedded macros or scripts, and enable Windows Defender Attack Surface Reduction rules for process hollowing and DLL sideloading. The NCSC provides detection YARA rules and behavior-based indicators in its public advisory dated 2019.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.