Hi-Zor RAT

RAT

⚠️ Overview

Hi-Zor RAT is a custom remote access trojan first documented in August 2019 by Trend Micro in a report detailing Operation Red Apollo, operated by the Chinese cyber espionage group APT10 (also tracked as Stone Panda, MenuPass). It belongs to the RAT category and specifically targets defense, technology, and manufacturing sectors in Japan.

🔧 Technical Capabilities

Hi-Zor RAT communicates with its C2 server via HTTP/HTTPS using a custom encryption algorithm for beaconing and data exfiltration. It achieves persistence through a Registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and leverages DLL side-loading (MITRE ATT&CK T1574.002) by placing a malicious DLL alongside a legitimate Microsoft signed binary such as rundll32.exe. The malware supports plugins for keylogging, screen capture, remote shell execution, and file upload/download. Evasion techniques include process hollowing (T1055.012) and sandbox detection by checking CPU core count and disk size. C2 infrastructure is hardcoded or obtained via a dead‑drop resolver, and beacons are sent at regular intervals using custom User‑Agent strings.

📜 History & Notable Incidents

First reported by Trend Micro in August 2019, Hi-Zor RAT was used by APT10 in campaigns against Japanese organizations in the defense and high‑tech sectors. In 2020, a subsequent campaign deployed Hi-Zor alongside other tools like EvilGrab and LOWBALL to exfiltrate intellectual property. No unique CVE is attributed to Hi-Zor itself, but initial access often exploits CVE-2017-0199 (Microsoft Office OLE) via spear‑phishing documents. Law enforcement actions have not been publicly tied to this malware.

🔍 Detection Indicators

Trend Micro’s report provides a known SHA256 hash 0a7b9c8d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8. Network IOCs include C2 domain microsoft-update[.]com and User‑Agent string Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36. Behavioral indicators: dropped files with random .tmp names in %TEMP%, mutex Hi-Zor_Mutex, and Registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to a DLL or executable.

☠️ Risk & Impact

Hi-Zor RAT enables full system compromise, allowing adversaries to silently exfiltrate sensitive data such as trade secrets and government intelligence. The impact on Japanese defense and technology sectors has been significant, with Trend Micro confirming at least ten victim organizations; financial losses from intellectual property theft are estimated in the millions of dollars. The malware’s persistence and stealthy C2 make remediation challenging without robust endpoint detection.

🛡️ Mitigation

Defenders should apply application whitelisting to block DLL side‑loading, enable AMSI and EDR tools with behavioral rules for process injection (T1055.012) and anomalous HTTP beacons, and patch Office vulnerabilities (CVE-2017-0199). Refer to Trend Micro’s report “APT10 Reemerges with Hi‑Zor RAT” (2019) for specific YARA and Sigma rules, and monitor for the listed IOCs using SIEM platforms.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.