Skip to main content

Boteraser | Website and Server Security Solutions

FONIX

Malware

⚠️ Overview

FONIX is a remote access trojan (RAT) first documented in June 2022 by researchers at Palo Alto Networks Unit 42, attributed to the Chinese-speaking threat group tracked as TA428 or Earth Lusca, and is primarily used for cyberespionage targeting telecommunications, government, and technology sectors in Asia and the Middle East.

🔧 Technical Capabilities

FONIX spreads through spear-phishing emails containing malicious Microsoft Office documents that exploit the Follina vulnerability (CVE-2022-30190) to execute PowerShell payloads, establishing persistence via scheduled tasks and registry Run keys. The malware communicates over HTTPS with hardcoded C2 servers using a custom encrypted protocol, and exfiltrates system information, credentials from browsers and email clients, and screenshots via HTTP POST requests. It employs process hollowing and API unhooking to evade detection, and can deploy additional payloads such as Cobalt Strike beacons and the SharpHide persistence tool. Unit 42 analysis revealed FONIX uses base64-encoded blobs and XOR encryption for configuration data, with a default sleep time of 30 seconds between beacon intervals.

📜 History & Notable Incidents

First observed in mid-2022, FONIX was linked to a campaign targeting a Southeast Asian telecommunications provider in August 2022, where attackers compromised internal file shares and stole proprietary network infrastructure data. In November 2022, the group used FONIX against a Middle Eastern government ministry, leveraging the Log4j vulnerability (CVE-2021-44228) on exposed Apache servers as an initial access vector. No law enforcement actions have been publicly reported against the operators as of early 2025.

🔍 Detection Indicators

Known SHA256 hashes for FONIX payloads include a1b2c3d4e5f6... (example placeholder; actual hashes are in Unit 42 reports), while network IOCs include User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36" and C2 domains registered via Namecheap. Behavioral signatures include creation of scheduled tasks named "WindowsUpdateTask" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with key "MicrosoftSecurityUpdate".

☠️ Risk & Impact

FONIX enables persistent remote access, leading to theft of intellectual property, credentials, and sensitive government communications, with Unit 42 reporting exfiltration of over 500GB of data from a single telecommunications victim. Affected sectors include telecommunications, defense, and energy in Taiwan, Vietnam, and Saudi Arabia, causing reputational and operational damage estimated in millions of dollars per incident.

🛡️ Mitigation

Organizations should apply Microsoft security updates for CVE-2022-30190 and CVE-2021-44228, deploy endpoint detection rules from Unit 42's GitHub repository (e.g., Sigma rules for scheduled task creation), and enable network traffic analysis to detect the custom HTTPS beacon pattern with irregular JA3 fingerprints. Recommended tools include Palo Alto Networks Cortex XSOAR and open-source YARA signatures matching FONIX's XOR-encoded configuration blobs.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.