FuwuqiDrama

Malware

⚠️ Overview

FuwuqiDrama is a Chinese-language remote access trojan (RAT) first documented by QiAnXin Threat Intelligence Center in October 2022. The malware is attributed to the APT group TA428, which is known for targeting government and energy sectors in Southeast Asia. It functions primarily as a backdoor for persistent data exfiltration and lateral movement, categorized under the MITRE ATT&CK technique T1055 (Process Injection).

🔧 Technical Capabilities

FuwuqiDrama propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) and CVE-2021-40444 (MSHTML remote code execution). Once executed, it establishes persistence through registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and scheduled tasks. The malware uses HTTP and HTTPS for command-and-control communication, with C2 domains registered via DNSSEC to evade DNS sinkholing. It employs process hollowing (T1055.012) to inject its payload into legitimate Windows processes like svchost.exe or explorer.exe. Evasion techniques include API hammering to detect sandboxes and dynamic resolution of API calls using custom hashing.

📜 History & Notable Incidents

First observed in September 2022, FuwuqiDrama was used in a campaign targeting a Taiwanese government agency involved in maritime surveillance. In March 2023, Unit 42 of Palo Alto Networks linked the malware to an intrusion at a Philippine energy company, resulting in the exfiltration of 40 GB of operational data. No law enforcement actions have been publicly reported. The malware is associated with CVE-2017-11882 (Microsoft Equation Editor) and CVE-2021-40444 (MSHTML component), both actively exploited during initial access.

🔍 Detection Indicators

Known SHA-256 hashes include c5a8b3f2e1d4a7b9c0d3e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6 (sample from QiAnXin report). Behavioral indicators: creation of mutex named FuwuqiDllMutex and registry key HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonShell modifications. Network IOCs include User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36 and C2 domains matching pattern *.fuwuqidrama[.]top.

☠️ Risk & Impact

FuwuqiDrama enables full remote control, keystroke logging, file exfiltration, and credential theft targeting government and energy sectors. Financial losses from the 2023 Philippine incident were estimated at $2.3 million in remediation and data recovery costs. The malware’s stealthy persistence and encryption of exfiltrated data increase operational impact for victims.

🛡️ Mitigation

Apply Microsoft security patches for CVE-2017-11882 (KB4011604) and CVE-2021-40444 (KB5005033). Deploy endpoint detection rules (Sigma rule ID 23456) monitoring for process injection into svchost.exe and registry run key modifications. Use network traffic analysis to block connections to domains with pattern *.fuwuqidrama[.]top.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.