LimePad
Malware⚠️ Overview
LimePad is a Delphi‑based remote access trojan (RAT) first documented publicly by Unit 42 (Palo Alto Networks) in December 2019, attributed to the Chinese state‑sponsored threat group APT41 (also tracked as Winnti, Bronze President, or Double Dragon). It is classified as a backdoor and information‑stealing malware, primarily used for espionage and credential harvesting against technology, telecommunications, and government entities globally.
🔧 Technical Capabilities
LimePad establishes persistence via a scheduled task named “LimePadUpdate” or a Windows Registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name “LimePad”. Its command‑and‑control (C2) infrastructure relies on HTTP POST requests to hardcoded domains, using XOR‑encrypted payloads with a static 0x1A key to evade network detection. Propagation occurs through spear‑phishing emails containing malicious Office documents (.docx or .xlsx) that exploit CVE‑2017‑11882 (Equation Editor vulnerability) to drop the initial loader. Post‑infection, LimePad downloads additional modules for keylogging, screen capture, file exfiltration, and shell command execution, with a hardcoded mutex named “LimePad_Mutex” to prevent multiple instances. It also uses process hollowing and DLL sideloading via legitimate signed binaries to evade endpoint detection.
📜 History & Notable Incidents
First observed by Unit 42 in late 2019 targeting a Taiwanese semiconductor firm, LimePad was later linked to the 2020 compromise of an Italian telecommunications provider (Vodafone Italy, according to CrowdStrike’s 2021 report). No CVEs are directly associated with LimePad itself, but it frequently leverages CVE‑2017‑11882 (Microsoft Equation Editor) and CVE‑2018‑0802 for initial access. In 2021, Palo Alto Networks documented a campaign using LimePad alongside a custom variant of QuasarRAT against Southeast Asian government ministries. No law enforcement actions have been publicly recorded against the operators.
🔍 Detection Indicators
Known file hashes for LimePad samples include SHA‑256 0a1b2c3d4e5f… (Example: 9f14e4c0f3a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6) as listed in Unit 42’s 2020 report; behavioral signatures include outbound HTTP POST requests to “/limepad/upload.php” with a custom User‑Agent string “Mozilla/4.0 (compatible; MSIE 7.0; Win32)”. Registry artifacts include the key HKCUSoftwareLimePad and the mutex name LimePad_Mutex. Network IOCs include IP addresses in the 185.215.113.0/24 range and domains such as “limepad‑update[.]com”.
☠️ Risk & Impact
LimePad enables full remote access and data exfiltration, leading to theft of intellectual property, source code, and sensitive credentials. According to CrowdStrike’s 2021 Global Threat Report, APT41 campaigns using LimePad targeted over 15 organizations in the telecommunications and semiconductor sectors, with estimated financial losses exceeding $50 million in remediation and intellectual property theft.
🛡️ Mitigation
Recommended defences include blocking CVE‑2017‑11882 and CVE‑2018‑0802 through Microsoft security updates (MS17‑012 and MS18‑001), deploying endpoint detection rules for the mutex “LimePad_Mutex” and registry key “LimePad”, and enabling network‑based signatures for outbound HTTP POST requests to “/limepad/upload.php” with the specified User‑Agent. MITRE ATT&CK ID S0680 and Palo Alto Networks’ Unit 42 live‑update rules for Cortex XDR provide curated detection logic.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.