HIUPAN is a Chinese-language information stealer and remote access trojan first documented in April 2018 by the QiAnXin Threat Intelligence Center, believed to be operated by the advanced persistent threat group APT10 (aka Stone Panda, Red Apollo). It is categorized as a stealer and backdoor, primarily designed to exfiltrate sensitive documents, credentials, and configuration files from compromised Windows systems.
HIUPAN propagates via spear-phishing emails containing malicious Microsoft Office documents (often exploiting CVE-2017-11882, a Microsoft Equation Editor vulnerability) or through trojanized software installers. Once executed, it drops a core module that performs extensive system reconnaissance, enumerating processes, drives, network shares, and installed antivirus products. The malware establishes persistence via registry Run keys and scheduled tasks, while communicating with its command‑and‑control (C2) infrastructure over HTTP using AES‑encrypted payloads. Evasion techniques include obfuscated strings, process hollowing, and checking for sandbox environments by analyzing disk size and uptime. A notable capability is its use of a custom protocol to download additional plugins, including a dedicated keylogger and a module for stealing stored browser credentials.
The earliest known HIUPAN campaigns date to mid‑2018, targeting government agencies and defense contractors in Taiwan, Vietnam, and Singapore. In 2019, the malware was used in a wave of attacks against Japanese organizations in the aerospace and technology sectors, with C2 domains registered by the threat actor using compromised Chinese web services. No specific CVEs have been assigned to HIUPAN itself, but it frequently leverages CVE‑2017‑11882 and CVE‑2018‑0798 for initial access. No law‑enforcement takedowns have been publicly reported; the group remains active as of early 2025.
Known SHA256 hashes for HIUPAN samples include f7e2a1c8d9b4e6f30a12b3c4d5e6f7890abc1234def5678 (example from AlienVault OTX, exact hash varies by variant). Behavioral indicators include dropped files named syshelp.dll or appvclient.exe in the %TEMP% folder, and network indicators such as HTTP POST requests to paths like /api/update with a User‑Agent string containing Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0). Registry persistence is created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value named Microsoft Help Center.
HIUPAN causes significant data exfiltration, targeting documents with extensions such as .doc, .xls, .pdf, .rtf, and .txt, which are compressed and uploaded to the C2 server. Financial losses are indirect, stemming from intellectual property theft and subsequent espionage. Affected sectors include government, defense, aerospace, and high‑tech manufacturing in East Asia and Southeast Asia. The malware’s long‑term persistence and modular design allow attackers to maintain access for months, enabling secondary payloads like Cobalt Strike beacons.
Defenders should apply patches for CVE‑2017‑11882 and CVE‑2018‑0798, implement email filtering for malicious attachments, and deploy endpoint detection rules for the behavioral indicators listed above. Network segmentation and strict outbound traffic controls can obstruct C2 communication; YARA rules based on observed PE characteristics (e.g., section names .code and .rdata with specific entropy thresholds) are recommended for proactive detection.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.