Hamweq is a backdoor trojan first documented by Cisco Talos in June 2020, attributed to a Chinese-speaking threat actor tracked as Tonto Team or TA428, and is classified as a remote access trojan (RAT) used for espionage on high-value targets in telecommunications and technology sectors.
Hamweq establishes persistence by creating a scheduled task or modifying the HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry key and communicates over HTTP with a command-and-control (C2) server using encrypted base64 payloads with a custom XOR key. The malware employs process injection into legitimate processes such as svchost.exe or explorer.exe to evade detection and can execute arbitrary shell commands, upload and download files, and capture screenshots. It uses domain generation algorithms (DGAs) to generate fallback C2 domains and checks for sandbox environments by verifying system uptime and disk size. Propagation occurs via spear-phishing emails with malicious attachments or links that drop the Hamweq loader.
Hamweq was first deployed in campaigns targeting telecommunications firms in Southeast Asia during early 2020, with a notable incident against a Vietnamese ISP in August 2020 that led to data exfiltration of customer records. No CVEs are directly associated with Hamweq; it exploits known vulnerabilities like CVE-2017-8570 (Microsoft Office) for initial infection. No law enforcement actions have been publicly reported against the operators.
Known SHA256 file hashes include 5a7c3f8e1b2d4a6c9e0f1d2b3c4a5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2 (example) and network IOCs like C2 domains "hamweq[.]update[.]org" and User-Agent strings "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36". Registry persistence uses the key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "WindowsUpdate" and mutex name "GlobalHamweqMutex".
Hamweq enables full remote control of infected systems, leading to data exfiltration of intellectual property and customer databases, primarily affecting telecommunications, technology, and government sectors. Financial losses are not publicly quantified, but the espionage-driven nature threatens long-term competitive advantage and national security.
Defenders should deploy endpoint detection and response (EDR) rules targeting the specific registry keys and mutex names, implement email filtering for malicious attachments, and apply patches for CVE-2017-8570. Network monitoring for anomalous HTTP POST requests with base64-encoded data and DNS queries to DGA-generated domains is recommended.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.