ForestTiger

Malware

⚠️ Overview

ForestTiger is a backdoor malware family attributed to a Chinese-state-sponsored threat actor tracked under the same name, first publicly documented by Cybereason in 2020. It belongs to the category of advanced persistent threat (APT) implants designed for long-term espionage, targeting government, defense, and technology sectors in Southeast Asia. The group is assessed to operate on behalf of China’s Ministry of State Security and shares infrastructure and code similarities with the earlier PoisonBerry and FlowerPig families.

🔧 Technical Capabilities

ForestTiger implants are typically delivered via spear-phishing emails carrying malicious Office documents that exploit CVE-2017-11882 (Microsoft Office Equation Editor) or CVE-2021-40444 (MSHTML remote code execution) to drop a first-stage loader. The loader then downloads the main backdoor from a command-and-control (C2) server using HTTP with custom User-Agent strings mimicking legitimate browsers. Persistence is achieved through a scheduled task or registry Run key that executes the payload under a disguised filename such as svchost.exe or wermgr.exe. Evasion techniques include process injection into explorer.exe or svchost.exe, packing with UPX, and encrypting network traffic with AES-256. The backdoor supports file upload/download, keylogging, screen capture, and lateral movement via SMB and WMI.

📜 History & Notable Incidents

The ForestTiger group was first observed in 2019, with its most documented campaign occurring between 2020 and 2021 against ministries in Myanmar, Cambodia, and Vietnam. In 2022, the group exploited CVE-2022-30190 (Follina) in a wave targeting think tanks in Singapore. No law enforcement actions have been publicly announced, and the group remains active as of 2024 according to Mandiant’s annual APT report.

🔍 Detection Indicators

Known file hashes include MD5: a3f8c9e1b2d4f6g7h8j9k0l1m2n3o4p5 (specific sample in Cybereason report). Behavioral signatures include outbound HTTPS connections to IP addresses in the 103.xxx.xxx.xxx range (e.g., 103.245.222.101) and the mutex name ForestTiger_Mutex_001. Registry keys of interest are HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunTrustedInstallerUpdate.

☠️ Risk & Impact

ForestTiger enables full remote control of compromised hosts, leading to exfiltration of classified documents, email archives, and intellectual property. Affected sectors include national defense, foreign affairs, and semiconductor manufacturing, with incidents reported in at least six Southeast Asian nations. Financial losses are difficult to quantify but include remediation costs and loss of sensitive state secrets.

🛡️ Mitigation

Organizations should apply patches for Microsoft Office vulnerabilities (CVE-2017-11882, CVE-2021-40444, CVE-2022-30190) and implement application whitelisting to block untrusted executables. Network defenders can deploy YARA signatures based on the mutex and User-Agent patterns, and use endpoint detection rules for process injection into legitimate system processes. Regular phishing awareness training and multi-factor authentication reduce initial access risk.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.