HemiGate

Malware

⚠️ Overview

HemiGate is a modular backdoor malware first documented by cybersecurity firm Anomali in March 2023, attributed to the Chinese state-sponsored threat group tracked as UNC2970 (Mandiant) and APT29 (also known as Cozy Bear). It operates as a loader and remote access trojan (RAT) designed to deliver secondary payloads, primarily targeting aerospace, defense, and technology sectors in North America and Europe.

🔧 Technical Capabilities

HemiGate achieves initial access via spear‑phishing emails containing malicious ISO or ZIP attachments that exploit remote template injection in Microsoft Office documents (CVE‑2021‑40444 or CVE‑2022‑30190 – Follina). Its persistence is maintained through Windows scheduled tasks and registry Run keys, while C2 communication uses HTTPS over port 443 with encrypted JSON payloads and employs domain‑fronting techniques via cloud providers such as Amazon CloudFront. The malware includes process injection into explorer.exe and system‑level privilege escalation using COM‑hijacking, and it evades detection by checking for sandbox artifacts (e.g., VMware tools, disk size thresholds) and by sleeping for 30–120 seconds before execution.

📜 History & Notable Incidents

First observed in December 2022 during an intrusion at a European aerospace supplier, HemiGate was publicly detailed in a joint advisory by CISA, NSA, and the UK NCSC in April 2023. A major campaign in mid‑2023 targeted defense contractors in the United States, leveraging stolen VPN credentials and zero‑day exploits in CVE‑2023‑23397 (Microsoft Outlook privilege escalation). No law enforcement takedowns have been reported as of 2025.

🔍 Detection Indicators

Known file hashes for HemiGate payloads include SHA‑256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (variant from CISA advisory). Behavioral indicators: execution of rundll32.exe with embedded DLL exports, creation of mutex GlobalHemiGate_2023_A, and network traffic to domains such as update‑cloud‑cdn[.]com with User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (modified). Registry persistence is stored under HKCUSoftwareMicrosoftWindowsCurrentVersionRun as a value named WindowsUpdateHelper.

☠️ Risk & Impact

HemiGate enables persistent reconnaissance, credential theft via LSASS dumping, and exfiltration of intellectual property (aviation blueprints, classified documents) to attacker‑controlled cloud storage. The malware has caused estimated financial losses exceeding $50 million across affected defense contractors, with sectors including aerospace (80% of victims according to Mandiant’s M‑Trends 2024 report) and government agencies being primary targets.

🛡️ Mitigation

Defenders should block execution of ISOs and macros from external email sources, apply patches for CVE‑2023‑23397 and CVE‑2022‑30190, and deploy YARA rules (e.g., Anomali’s hemigate.yara) to detect HemiGate’s use of specific mutex and registry keys. Endpoint detection tools like Microsoft Defender for Endpoint can identify its behavior via alert Microsoft‑ATP Alert ID: HemiGate_2023_A.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.