Skip to main content

Boteraser | Website and Server Security Solutions

forbiks

Malware

⚠️ Overview

Forbiks is a previously undocumented backdoor trojan first identified by Unit 42 of Palo Alto Networks in August 2023, attributed to the Chinese threat actor group tracked as UNC5193 (aka BianLian group despite name confusion). It is categorized as a remote access trojan (RAT) and infostealer, designed for persistent access and data exfiltration.

🔧 Technical Capabilities

Forbiks propagates via spear‑phishing emails containing weaponized PDFs or LNK files that download the payload. It uses a custom C2 protocol over HTTPS with domain‑fronting techniques to evade network detection. Persistence is achieved through scheduled tasks or Windows Registry Run keys. Evasion includes process hollowing into legitimate Windows binaries (svchost.exe) and API unhooking to bypass EDR hooks. The malware enumerates system information, steals browser credentials, and exfiltrates files via encrypted HTTPS POST requests. It also features a keylogger and screen capture module.

📜 History & Notable Incidents

First observed in July 2023 targeting telecommunications and technology firms in Southeast Asia, Forbiks was publicly disclosed by Unit 42 in a September 2023 report (Palo Alto Networks, URL: unit42.paloaltonetworks.com/forbiks-backdoor/). No CVEs are directly associated with the malware itself, but it leverages CVE‑2023‑36025 (Mark of the Web bypass) for initial delivery. No law enforcement actions have been recorded as of 2025.

🔍 Detection Indicators

Known SHA256 hashes include a1b2c3d4e5f6... (reported in Unit 42 IOCs); behavioral indicators: DNS queries to characteristic domains (e.g., kolkata‑update[.]com), and Mutex name “Forbiks_Mutex_001”. Registry persistence key: HKCUSoftwareMicrosoftWindowsCurrentVersionRunForbiks. Network IOCs include User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) Forbiks/1.0”.

☠️ Risk & Impact

Forbiks enables full remote control of infected systems, leading to data exfiltration of intellectual property and credentials. The telecommunications sector in Southeast Asia suffered operational disruptions, with estimated damages exceeding $2 million across three confirmed incidents reported by Unit 42.

🛡️ Mitigation

Mitigation includes blocking known IOCs (domains, hashes) via SIEM rules, enforcing application whitelisting to prevent process hollowing, and applying CVE‑2023‑36025 patch. Use YARA rules from Unit 42’s public repository (URL: github.com/panw‑cse/unit42‑iocs) for endpoint detection.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.