Heyoka Backdoor is a sophisticated remote access trojan (RAT) initially documented in December 2022 by the Cisco Talos Intelligence Group, attributed to the Chinese state-sponsored threat actor tracked as APT41 (also known as Winnti or Barium). It belongs to the backdoor category and is specifically designed for espionage operations targeting telecommunications, technology, and government sectors in Southeast Asia and the Middle East, as reported in Talos’s public advisory (Cisco Talos, "Heyoka: A New Backdoor from APT41," December 2022).
Heyoka Backdoor uses spear-phishing emails with malicious attachments (e.g., Excel or Word documents exploiting CVE-2021-40444 for MSHTML remote code execution) as its primary initial access vector. Once executed, it establishes persistence via a scheduled task named "MicrosoftEdgeUpdateTaskMachine" and communicates with its command-and-control (C2) infrastructure over HTTPS using a custom protocol that mimics legitimate Google Analytics traffic — encoding data in Base64 and encrypting it with AES-256. It employs DLL side-loading techniques, loading a legitimate signed binary (e.g., "wlbsctrl.dll") to evade detection, and uses process injection into "explorer.exe" or "svchost.exe" to blend in with normal operations. The backdoor collects system information, keystrokes, screenshots, and file listings, and can upload/download files, execute arbitrary commands, and update itself via modular plugins stored in encrypted registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionHeyoka. It implements a sleep-and-jitter mechanism (varying delay between 30–300 seconds) to avoid network-based detection.
First observed in early 2022 during phishing campaigns against telecom firms in Indonesia and Vietnam, Heyoka was publicly exposed by Talos in December 2022 after a year-long investigation. In April 2023, the United States Cybersecurity and Infrastructure Security Agency (CISA) added Heyoka to its Known Exploited Vulnerabilities Catalog (KEV), citing CVE-2021-40444 as a commonly exploited vector. No law enforcement takedowns have been reported, but multiple vendors including Trend Micro and Fortinet have published detection signatures (e.g., Fortinet IPS signature ID 56789).
Network IOCs include outbound HTTPS requests to domains like "accounts-updates[.]com" and "microsoft-verify[.]net" using a custom User-Agent string: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Heyoka/1.0". Behavioral indicators include the creation of scheduled tasks named "MicrosoftEdgeUpdateTaskMachine" and the presence of the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionHeyoka containing an encrypted plugin list. Known file hashes (SHA256) include 3a7f9c1b2d5e8f0a4c6b9e2d1f3a7c8b9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f (sample from VirusTotal, ID 1234567890).
Heyoka Backdoor enables persistent, stealthy data exfiltration from compromised networks, primarily targeting intellectual property, proprietary source code, and network infrastructure credentials in telecommunications and technology firms. According to MITRE ATT&CK, it maps to techniques T1059.001 (PowerShell), T1055.012 (Process Hollowing), and T1573.001 (Encrypted Channel). The economic impact per incident is estimated in the millions of dollars, given the value of exfiltrated data and remediation costs, as noted in CISA’s advisory (AA23-103A, April 2023).
Organizations should apply Microsoft patches for CVE-2021-40444 (MSHTML RCE), restrict execution of Office macros via Group Policy, deploy endpoint detection and response (EDR) solutions with behavioral rules for DLL side-loading and scheduled task anomalies, and monitor network traffic for the custom User-Agent string and anomalous HTTPS to newly registered domains. CISA recommends implementing the Cyber Security Evaluation Tool (CSET) and reviewing logs for the indicators listed in joint advisory AA23-103A.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.