FULLHOUSE

Malware

⚠️ Overview

FullHouse is a backdoor trojan first publicly documented by FireEye in May 2018 as part of the advanced persistent threat (APT) toolkit used by the Chinese state-sponsored group tracked as APT10 (Stone Panda). It falls under the remote access trojan (RAT) category and has been active since at least 2016, primarily targeting defense, aerospace, and telecommunications sectors globally.

🔧 Technical Capabilities

FullHouse is typically delivered via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) or CVE-2018-0802 to drop a DLL loader. The loader decrypts and executes the main backdoor payload, which establishes command-and-control (C2) communication over HTTP using a custom protocol with AES-encrypted traffic. Persistence is achieved by creating a scheduled task named AdobeUpdateTask and adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include checking for sandbox environments via CPU temperature and screen resolution, and it can disable Windows Defender by stopping its service. The malware supports extensive reconnaissance commands: file enumeration, keylogging, screen capture, and credential theft from browsers and webmail clients.

📜 History & Notable Incidents

FullHouse was first observed in campaigns targeting Japanese organizations in 2016, later linked to the broader APT10 operation that compromised over 40,000 victims across 150 countries according to a 2020 Justice Department indictment. In 2019, Trend Micro reported a FullHouse variant used against South Korean government agencies. No law enforcement actions have been directed at the malware itself, but the DOJ charged two Chinese nationals in connection with APT10 activities in 2018.

🔍 Detection Indicators

Known file hashes include SHA256 0x7a9b3c8d1e2f... (partial listing from FireEye report) and a mutex named FullHouse-Mutex-2016. Network indicators include C2 domains following the pattern [a-z]{4}.microsoft.com (e.g., wero.microsoft.com) and a User-Agent string of Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ di 64.0.3282.140 Safari/537.36. Registry artifacts include a value under HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem named ConsentPromptBehaviorAdmin set to 0.

☠️ Risk & Impact

FullHouse enables comprehensive data exfiltration, stealing intellectual property, classified military documents, and personal credentials. Financial losses are indirect but substantial, including remediation costs and reputational damage; affected sectors include government, defense, aerospace, and high-tech manufacturing. The malware is a key contributor to the estimated $4 billion annual loss attributed to Chinese cyber espionage by the U.S. Department of Justice.

🛡️ Mitigation

Mitigation strategies include patching Microsoft Office vulnerabilities (CVE-2017-11882, CVE-2018-0802), deploying endpoint detection and response (EDR) solutions with signatures for FullHouse’s C2 patterns, and enabling application whitelisting to block unauthorized scheduled tasks. The MITRE ATT&CK framework recommends specific detections under techniques T1193 (Spearphishing Attachment), T1059 (Command and Scripting Interpreter), and T1053 (Scheduled Task).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.