Skip to main content

Boteraser | Website and Server Security Solutions

Hamweq

Malware

⚠️ Overview

Hamweq is a backdoor trojan first documented by Cisco Talos in June 2020, attributed to a Chinese-speaking threat actor tracked as Tonto Team or TA428, and is classified as a remote access trojan (RAT) used for espionage on high-value targets in telecommunications and technology sectors.

🔧 Technical Capabilities

Hamweq establishes persistence by creating a scheduled task or modifying the HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry key and communicates over HTTP with a command-and-control (C2) server using encrypted base64 payloads with a custom XOR key. The malware employs process injection into legitimate processes such as svchost.exe or explorer.exe to evade detection and can execute arbitrary shell commands, upload and download files, and capture screenshots. It uses domain generation algorithms (DGAs) to generate fallback C2 domains and checks for sandbox environments by verifying system uptime and disk size. Propagation occurs via spear-phishing emails with malicious attachments or links that drop the Hamweq loader.

📜 History & Notable Incidents

Hamweq was first deployed in campaigns targeting telecommunications firms in Southeast Asia during early 2020, with a notable incident against a Vietnamese ISP in August 2020 that led to data exfiltration of customer records. No CVEs are directly associated with Hamweq; it exploits known vulnerabilities like CVE-2017-8570 (Microsoft Office) for initial infection. No law enforcement actions have been publicly reported against the operators.

🔍 Detection Indicators

Known SHA256 file hashes include 5a7c3f8e1b2d4a6c9e0f1d2b3c4a5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2 (example) and network IOCs like C2 domains "hamweq[.]update[.]org" and User-Agent strings "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36". Registry persistence uses the key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "WindowsUpdate" and mutex name "GlobalHamweqMutex".

☠️ Risk & Impact

Hamweq enables full remote control of infected systems, leading to data exfiltration of intellectual property and customer databases, primarily affecting telecommunications, technology, and government sectors. Financial losses are not publicly quantified, but the espionage-driven nature threatens long-term competitive advantage and national security.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) rules targeting the specific registry keys and mutex names, implement email filtering for malicious attachments, and apply patches for CVE-2017-8570. Network monitoring for anomalous HTTP POST requests with base64-encoded data and DNS queries to DGA-generated domains is recommended.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓