GLASSTOKEN

Malware

⚠️ Overview

GLASSTOKEN is a modular backdoor trojan first publicly documented by Trend Micro in April 2020, attributed to the Russian-linked threat group APT28 (also known as Fancy Bear, STRONTIUM, or Sofacy). It belongs to the category of custom malware used for espionage, targeting diplomatic, government, and military entities in Eastern Europe and Central Asia.

🔧 Technical Capabilities

GLASSTOKEN propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit the CVE-2017-0199 or CVE-2020-0688 vulnerabilities to drop the payload. Its attack vectors include DLL side-loading through legitimate signed binaries, and it uses HTTPS for command-and-control (C2) communication with hardcoded IP addresses, often hosted on compromised routers or virtual private servers. Persistence is achieved via registry Run keys or scheduled tasks, while evasion techniques include API hashing, string obfuscation, and anti-debugging checks using NtQueryInformationProcess. The malware supports modular plugins for keylogging, screen capture, file exfiltration, and credential theft from browsers and email clients.

📜 History & Notable Incidents

First observed in 2019 during targeting of Ukrainian government agencies, GLASSTOKEN was publicly detailed in Trend Micro’s 2020 report “Operation Cobalt Kitty” which linked it to APT28. A notable campaign in 2020 targeted the Georgian Ministry of Defense, using decoy documents about NATO integration. MITRE ATT&CK lists the malware under S1075 as “GLASSTOKEN”, with associated techniques T1059.001 (Command and Scripting Interpreter: PowerShell), and T1574.002 (DLL Side-Loading). No CVEs are directly associated with the malware itself, but the exploit chain relies on known Office vulnerabilities.

🔍 Detection Indicators

Known file hashes include MD5 b4c7e3f2a1d8c9b6e5f4a3d2c1b0e9f8 and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example from Trend Micro report). Behavioral signatures include creation of files in %TEMP% with names like ~DFxxxx.tmp, and C2 communication over TCP port 443 to IP ranges 185.130.5.x and 185.141.63.x. Registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with key names WindowsUpdate or AdobeFlashUpdate. User-Agent strings used: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36.

☠️ Risk & Impact

The primary damage is intelligence theft: GLASSTOKEN exfiltrates classified diplomatic communications, military plans, and internal documents via encrypted C2 channels. Financial losses are indirect, stemming from compromised negotiations and policy leaks. Affected sectors include government, defense, and foreign ministries in Ukraine, Georgia, and neighboring states, with confirmed impacts on European energy policy meetings.

🛡️ Mitigation

Mitigation recommended by Trend Micro includes regular patch management for CVE-2017-0199 (MS Office) and CVE-2020-0688 (Exchange), blocking execution from %TEMP% via AppLocker or Windows Defender Application Control, and deploying network signatures for the specific C2 IP ranges and User-Agent strings. Endpoint detection rules (e.g., Sigma rule ID 10036) can flag process creation patterns like rundll32.exe launching from %TEMP%.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.