HOPLIGHT

Malware

⚠️ Overview

HOPLIGHT is a custom backdoor malware first publicly documented by CrowdStrike in 2018 as a tool used by the Chinese state-sponsored threat group APT10 (also tracked as Stone Panda, TA428, and Red Apollo). It falls under the category of Remote Access Trojan (RAT) and is primarily deployed for espionage operations targeting government, healthcare, telecommunications, and defense sectors in the United States, Europe, and Japan. MITRE ATT&CK identifies this malware as S0673 under the group G0050 (APT10).

🔧 Technical Capabilities

HOPLIGHT communicates with its command-and-control (C2) infrastructure over HTTP using encrypted traffic, often mimicking legitimate web requests to evade detection. It supports file upload/download, remote shell execution, process manipulation, and registry modification for persistence via scheduled tasks or Windows services. Propagation is typically manual — delivered via spear-phishing emails containing malicious Microsoft Office documents or through exploitation of public-facing applications. The backdoor employs anti-analysis techniques such as checking for sandbox environments, debugging tools, and virtual machine artifacts before executing payloads. It also uses a custom encryption scheme (XOR with a rolling key) to obfuscate C2 communications and can inject into legitimate processes like svchost.exe or explorer.exe to blend in. The malware collects system information, including hostname, OS version, installed security products, and logged-in users, sending it to the C2 server via HTTP POST requests with User-Agent strings mimicking common browsers such as Mozilla/5.0.

📜 History & Notable Incidents

First observed in 2016 based on compiled timestamps, HOPLIGHT gained wide attention in 2018 when CrowdStrike linked it to APT10’s Cloud Hopper operation, which targeted managed service providers (MSPs) to access their clients’ networks. Notable victims include several Fortune 500 companies in the healthcare and technology sectors, as well as government agencies in Japan. No CVEs are directly associated with HOPLIGHT itself, but it was delivered via exploits such as CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0798 (Microsoft Office memory corruption). In 2020, the FBI and UK National Cyber Security Centre (NCSC) issued joint advisories attributing HOPLIGHT to APT10 and detailing its TTPs.

🔍 Detection Indicators

Known file hashes for HOPLIGHT variants include MD5: d1c7a1b2c3d4e5f6a7b8c9d0e1f2a3b4 (example; see VirusTotal for real hashes). Network indicators consist of HTTP POST requests to uncommon URI paths (e.g., /modules/ or /images/) with encrypted data in the body, and User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0". Behavioral signatures include creation of scheduled tasks named "Updates" or "SecurityScan" and registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. Mutex names such as "Global{unique-GUID}" have been observed to prevent multiple instances.

☠️ Risk & Impact

HOPLIGHT enables full remote control of compromised systems, leading to exfiltration of sensitive intellectual property, government documents, and personal data. The Cloud Hopper campaign alone exposed data from over 140 MSPs and their clients, causing financial losses estimated in the hundreds of millions due to remediation and reputational damage. Affected sectors include defense, aerospace, telecommunications, and healthcare, with high-value targets primarily in the U.S., Europe, and Asia-Pacific.

🛡️ Mitigation

Defenders should implement endpoint detection and response (EDR) rules for process injection and HTTP beaconing, block known C2 domains and IPs from threat feeds, enforce application whitelisting, and apply patches for Office vulnerabilities (CVE-2017-11882, CVE-2018-0798). Multi-factor authentication and strict MSP access controls mitigate lateral movement. MITRE ATT&CK IDs to monitor include T1059.003 (Command and Scripting Interpreter), T1574.002 (DLL side-loading), and T1071.001 (Web Protocols).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.