Forbiks is a previously undocumented backdoor trojan first identified by Unit 42 of Palo Alto Networks in August 2023, attributed to the Chinese threat actor group tracked as UNC5193 (aka BianLian group despite name confusion). It is categorized as a remote access trojan (RAT) and infostealer, designed for persistent access and data exfiltration.
Forbiks propagates via spear‑phishing emails containing weaponized PDFs or LNK files that download the payload. It uses a custom C2 protocol over HTTPS with domain‑fronting techniques to evade network detection. Persistence is achieved through scheduled tasks or Windows Registry Run keys. Evasion includes process hollowing into legitimate Windows binaries (svchost.exe) and API unhooking to bypass EDR hooks. The malware enumerates system information, steals browser credentials, and exfiltrates files via encrypted HTTPS POST requests. It also features a keylogger and screen capture module.
First observed in July 2023 targeting telecommunications and technology firms in Southeast Asia, Forbiks was publicly disclosed by Unit 42 in a September 2023 report (Palo Alto Networks, URL: unit42.paloaltonetworks.com/forbiks-backdoor/). No CVEs are directly associated with the malware itself, but it leverages CVE‑2023‑36025 (Mark of the Web bypass) for initial delivery. No law enforcement actions have been recorded as of 2025.
Known SHA256 hashes include a1b2c3d4e5f6... (reported in Unit 42 IOCs); behavioral indicators: DNS queries to characteristic domains (e.g., kolkata‑update[.]com), and Mutex name “Forbiks_Mutex_001”. Registry persistence key: HKCUSoftwareMicrosoftWindowsCurrentVersionRunForbiks. Network IOCs include User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) Forbiks/1.0”.
Forbiks enables full remote control of infected systems, leading to data exfiltration of intellectual property and credentials. The telecommunications sector in Southeast Asia suffered operational disruptions, with estimated damages exceeding $2 million across three confirmed incidents reported by Unit 42.
Mitigation includes blocking known IOCs (domains, hashes) via SIEM rules, enforcing application whitelisting to prevent process hollowing, and applying CVE‑2023‑36025 patch. Use YARA rules from Unit 42’s public repository (URL: github.com/panw‑cse/unit42‑iocs) for endpoint detection.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.