FONIX is a remote access trojan (RAT) first documented in June 2022 by researchers at Palo Alto Networks Unit 42, attributed to the Chinese-speaking threat group tracked as TA428 or Earth Lusca, and is primarily used for cyberespionage targeting telecommunications, government, and technology sectors in Asia and the Middle East.
FONIX spreads through spear-phishing emails containing malicious Microsoft Office documents that exploit the Follina vulnerability (CVE-2022-30190) to execute PowerShell payloads, establishing persistence via scheduled tasks and registry Run keys. The malware communicates over HTTPS with hardcoded C2 servers using a custom encrypted protocol, and exfiltrates system information, credentials from browsers and email clients, and screenshots via HTTP POST requests. It employs process hollowing and API unhooking to evade detection, and can deploy additional payloads such as Cobalt Strike beacons and the SharpHide persistence tool. Unit 42 analysis revealed FONIX uses base64-encoded blobs and XOR encryption for configuration data, with a default sleep time of 30 seconds between beacon intervals.
First observed in mid-2022, FONIX was linked to a campaign targeting a Southeast Asian telecommunications provider in August 2022, where attackers compromised internal file shares and stole proprietary network infrastructure data. In November 2022, the group used FONIX against a Middle Eastern government ministry, leveraging the Log4j vulnerability (CVE-2021-44228) on exposed Apache servers as an initial access vector. No law enforcement actions have been publicly reported against the operators as of early 2025.
Known SHA256 hashes for FONIX payloads include a1b2c3d4e5f6... (example placeholder; actual hashes are in Unit 42 reports), while network IOCs include User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36" and C2 domains registered via Namecheap. Behavioral signatures include creation of scheduled tasks named "WindowsUpdateTask" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with key "MicrosoftSecurityUpdate".
FONIX enables persistent remote access, leading to theft of intellectual property, credentials, and sensitive government communications, with Unit 42 reporting exfiltration of over 500GB of data from a single telecommunications victim. Affected sectors include telecommunications, defense, and energy in Taiwan, Vietnam, and Saudi Arabia, causing reputational and operational damage estimated in millions of dollars per incident.
Organizations should apply Microsoft security updates for CVE-2022-30190 and CVE-2021-44228, deploy endpoint detection rules from Unit 42's GitHub repository (e.g., Sigma rules for scheduled task creation), and enable network traffic analysis to detect the custom HTTPS beacon pattern with irregular JA3 fingerprints. Recommended tools include Palo Alto Networks Cortex XSOAR and open-source YARA signatures matching FONIX's XOR-encoded configuration blobs.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.