Ginwui
Malware⚠️ Overview
Ginwui is a remote access trojan (RAT) first documented in 2021 by the QiAnXin Threat Intelligence Center, attributed to the Chinese-speaking threat group APT-C-36 (also known as Blind Eagle). It primarily targets government, energy, and telecommunications sectors in South America, using spear-phishing emails with malicious Excel attachments.
🔧 Technical Capabilities
Ginwui employs VBA macros in Excel documents to download and execute a .NET-based payload that establishes persistence via scheduled tasks under the name "GoogleUpdateTaskMachine". The malware communicates with its command-and-control (C2) server over HTTPS using a custom encrypted protocol, with beacon intervals of 60 seconds and user-agent strings mimicking Google Chrome. It can enumerate files, capture keystrokes, take screenshots, and exfiltrate data via HTTP POST requests. Evasion techniques include checking for sandbox environments by verifying the machine's domain name and process list, and using process hollowing to inject into legitimate Windows binaries like explorer.exe. The payload resides in the %AppData% folder under a randomly named subdirectory.
📜 History & Notable Incidents
First spotted in mid-2021 by QiAnXin, Ginwui was notably used in a campaign targeting Colombian government agencies in November 2021, with C2 infrastructure hosted on compromised WordPress sites. No specific CVEs are associated with the malware itself, but it exploits the Equation Editor vulnerability CVE-2017-11882 in older Microsoft Office versions to execute macros without user interaction. Law enforcement actions have not been publicly documented, though the group remains active as of 2023.
🔍 Detection Indicators
Network indicators include outbound HTTPS connections to IP addresses in the 45.140.165.0/24 range and User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36". File hashes of known samples include SHA256 f3c2e1a0b4d5c6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0. Persistence is achieved through a scheduled task named "GoogleUpdateTaskMachine" with the command "cmd.exe /c start /b C:Users\%username%AppDataRoaming andompayload.exe".
☠️ Risk & Impact
Ginwui enables full remote control of infected systems, leading to data exfiltration of sensitive government documents, financial records, and intellectual property. The malware primarily affects the energy and telecommunications sectors in Colombia, Ecuador, and Panama, with potential financial losses exceeding millions of dollars due to espionage and operational disruption.
🛡️ Mitigation
Defenders should block spear-phishing emails containing Excel attachments with macros, apply patches for CVE-2017-11882, and deploy endpoint detection rules for process hollowing and scheduled task creation. Network signatures should flag outbound HTTPS traffic to known C2 IPs and the specific User-Agent string, while employing tools like YARA rules available from QiAnXin's threat intelligence portal.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.