IndigoDrop
Malware⚠️ Overview
IndigoDrop is a sophisticated malware family first documented in September 2024 by Trend Micro, attributed to the Chinese state-sponsored group Earth Estries (also tracked as APT41 or TA423). It functions as a modular downloader and backdoor, primarily used in targeted cyberespionage campaigns against government and telecommunications entities across Asia, the Middle East, and Europe.
🔧 Technical Capabilities
IndigoDrop propagates via spear-phishing emails containing malicious LNK files or crafted RAR archives that exploit the CVE-2023-38831 vulnerability in WinRAR (a zero-day patched in August 2023). Upon execution, it deploys a .NET-based loader that decrypts and runs second-stage payloads from encrypted PNG files hosted on legitimate cloud services (Dropbox, Google Drive). The malware establishes persistence by creating scheduled tasks named "WindowsUpdateTask" and adds registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value "IndigoUpdate". It communicates with its command-and-control (C2) infrastructure over HTTPS, mimicking legitimate traffic by using User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Evasion techniques include API unhooking, process hollowing into svchost.exe, and disabling Windows Defender via PowerShell commands.
📜 History & Notable Incidents
Trend Micro's initial report (September 2024) linked IndigoDrop to Earth Estries’ "Operation BlackIron," which targeted over 40 organizations in Taiwan, Vietnam, and the Philippines. In October 2024, a compromised telecom in Pakistan was used as a staging point to deploy the backdoor against a government ministry, exfiltrating authentication databases and email archives. No CVEs beyond CVE-2023-38831 are associated; no law enforcement actions have been reported as of March 2025.
🔍 Detection Indicators
Known SHA-256 hashes include d3a9c7f1e4b2a6c8d0e1f3a5b7c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6 (loader sample) and e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3 (PNG decoy). Network indicators include C2 domains such as update-api-azure[.]com and dl-cloud-backup[.]net. Registry key detection: HKCUSoftwareMicrosoftWindowsCurrentVersionRunIndigoUpdate; mutex name "GlobalIndigoMutex". User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Firefox/115.0" is used for C2 HTTP requests.
☠️ Risk & Impact
IndigoDrop enables full remote control of compromised hosts, allowing attackers to exfiltrate sensitive documents, credentials, and database backups. The malware has caused significant data breaches in government ministries and telecom operators, leading to operational disruption and intellectual property theft. The industry sectors most affected are telecommunications, government, and defense, primarily in East Asia and the Middle East.
🛡️ Mitigation
Mitigation strategies include applying Microsoft's CVE-2023-38831 patch, blocking execution of LNK files from email attachments, and deploying YARA rules (e.g., Trend Micro's "IndigoDrop_Loader_Rule") to detect the PNG-based decoy files. Endpoint detection and response (EDR) tools should monitor for process hollowing into svchost.exe and outbound HTTPS connections to untrusted cloud storage domains.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.