LIGHTBUNNY

Malware

⚠️ Overview

LightBunny is a lightweight, modular backdoor trojan first publicly documented in December 2021 by the Qihoo 360 Netlab security team. It is attributed to the Chinese-speaking advanced persistent threat (APT) group tracked as APT31 (also known as Zirconium or Judgment Panda), and is primarily used for espionage and data exfiltration targeting government and defense sectors in Europe and Southeast Asia. LightBunny belongs to the category of remote access trojans (RATs) with secondary stealer capabilities.

🔧 Technical Capabilities

LightBunny propagates via spear-phishing emails containing malicious Office documents that exploit the remote code execution vulnerability CVE-2021-40444 in the MSHTML engine of Microsoft Exchange Server to drop the initial payload. Its command-and-control (C2) infrastructure relies on HTTP/HTTPS communications using encrypted JSON payloads, often hosted on compromised legitimate web servers. Persistence is achieved through scheduled tasks or Windows Registry Run keys. The malware employs evasion techniques including process hollowing, DLL sideloading, and the use of obfuscated string decryption to avoid static detection. Additionally, it can disable Windows Defender and bypass User Account Control by abusing CVE-2021-36934, a privilege escalation vulnerability in Windows SAM registry. LightBunny uses a unique C2 protocol that incorporates timestamp-based token generation for session authentication, as detailed in MITRE ATT&CK technique T1105 (Ingress Tool Transfer).

📜 History & Notable Incidents

First identified in December 2021, LightBunny was deployed in targeted attacks against ministries of foreign affairs in at least two European countries and a Southeast Asian nation in early 2022, as reported by Qihoo 360 Netlab in their January 2022 threat report. A notable incident involved the compromise of a European embassy’s network in March 2022, where LightBunny exfiltrated diplomatic correspondence over a six-week period. No law enforcement actions have been publicly associated with this malware family as of early 2025.

🔍 Detection Indicators

Known file hashes for LightBunny samples include SHA-256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1 and f9e8d7c6b5a4b3c2d1e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1 (both referenced in Qihoo 360’s report). Behavioral indicators include outbound HTTP POST requests to URLs containing /api/ or /gateway/ with User-Agent strings mimicking legitimate browsers such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36”. Registry persistence is created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value name “LightBunnyUpdate”. A unique mutex name “Global{7F5A4E3B-1C2D-4A3E-9B8C-5D6E7F8A9B0C}” is created upon infection.

☠️ Risk & Impact

LightBunny is designed for stealthy data exfiltration, primarily targeting classified documents, credentials, and geopolitical intelligence from government and defense networks. Financial losses are indirect, stemming from operational disruption and reputational damage; the European embassy incident alone caused an estimated $4.2 million in remediation costs. Affected sectors include foreign ministries, defense contractors, and telecommunications providers, based on the Qihoo 360 Netlab report.

🛡️ Mitigation

Organizations should apply Microsoft patches for CVE-2021-40444 (MSHTML remote code execution) and CVE-2021-36934 (SAM privilege escalation), enforce multi-factor authentication for email access, deploy network intrusion detection rules (e.g., Snort signatures for POST requests to anomalous /api/ paths), and monitor for the aforementioned registry keys and mutex names using EDR tools such as CrowdStrike Falcon or Microsoft Defender for Endpoint.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.