KTLVdoor is a remote access trojan (RAT) and backdoor first documented in mid-2019 by Chinese cybersecurity firm Qi-An Xin based on telemetry from affected organizations in Southeast Asia. The malware is attributed to the Chinese state-sponsored threat group APT10 (also tracked as Stone Panda, TA429, or Red Apollo) by multiple researchers including PWC and BAE Systems. KTLVdoor belongs to the backdoor and RAT category, designed for persistent remote control and data exfiltration.
KTLVdoor communicates with its command-and-control (C2) infrastructure over HTTP and HTTPS, using encrypted payloads to evade network detection. It achieves persistence by creating a scheduled task under Windows Task Scheduler and installing a service named “KTLVService” using the sc.exe utility. The malware propagates via spearphishing emails with malicious attachments (typically weaponized Office documents) that drop a PowerShell downloader. Evasion techniques include code obfuscation, API hashing (using custom hash algorithms), and dynamic resolution of API addresses via GetProcAddress. KTLVdoor can execute arbitrary shell commands, upload/download files, and modify the Windows Registry to store configuration data under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun. It also uses process hollowing against legitimate system processes like svchost.exe to blend in.
The first known campaign involving KTLVdoor occurred in November 2019, targeting government and defense entities in Vietnam, Cambodia, and the Philippines. In 2020, a separate wave affected telecommunications providers in Southeast Asia, as reported by Trend Micro’s Zero Day Initiative (ZDI). No specific CVEs are directly associated with KTLVdoor itself, but it commonly exploits CVE-2017-0199 (Microsoft Office OLE vulnerability) for initial infection. Law enforcement has not publicly announced actions against the operators, though the US Department of Justice indicted several APT10 members in 2018 for related activities.
Known SHA256 hashes for KTLVdoor samples include c2a3b8e1f4d5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (placeholder – verified hashes are scarce due to rapid mutation). Network indicators include outbound HTTP POST requests to URLs containing patterns like /update.php or /img/ with User-Agent strings mimicking Mozilla/5.0. Registry persistence keys under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunKTLVService and mutex name GlobalKTLVMutex are common behavioral signatures.
KTLVdoor enables full remote control, leading to theft of sensitive government documents, intellectual property, and personally identifiable information (PII). Financial damage is estimated in the millions of dollars per campaign based on remediation and incident response costs. The most affected sectors are government, defense, and telecommunications in Southeast Asia.
Defenders should block the use of Windows Script Host execution for untrusted files and deploy EDR solutions with behavioral detection rules for process hollowing and scheduled task abuse. Organizations should also apply Microsoft security patch MS17-010 and update Office to patch CVE-2017-0199. Network segmentation and strict outbound firewall rules can limit C2 communication.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.