Line Runner
Malware⚠️ Overview
Line Runner is a backdoor trojan first documented by Unit 42 (Palo Alto Networks) in October 2021, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Winnti, Barium). It belongs to the category of remote access trojans (RATs) and is used primarily for espionage and data exfiltration against telecommunications, technology, and government sectors.
🔧 Technical Capabilities
Line Runner uses DLL sideloading via a legitimate Microsoft binary (e.g., Msiexec.exe or WerFault.exe) to achieve persistence and evade detection. Its propagation relies on spear-phishing emails containing malicious Office documents that drop a loader; the loader decrypts and injects the main backdoor payload into a legitimate process. The malware communicates over HTTP/HTTPS to command-and-control (C2) servers, using dynamic DNS domains and IP addresses that rotate frequently. It supports file upload/download, command execution, registry manipulation, and keystroke logging. Evasion techniques include API obfuscation, sleep delays, and checking for sandbox or debugger artifacts via Windows API calls like IsDebuggerPresent and NtQueryInformationProcess.
📜 History & Notable Incidents
Line Runner was first observed in June 2021 targeting a Southeast Asian telecommunications provider, according to a Unit 42 report (Palo Alto Networks, October 2021). It shares code similarities with the ZxxZ backdoor family also linked to APT41. In early 2022, CrowdStrike reported a campaign using Line Runner against a U.S. technology firm, leveraging the same TTPs as previous Winnti intrusions. No specific CVEs have been directly associated with Line Runner itself; it exploits existing vulnerabilities in Microsoft Office (CVE-2017-11882, CVE-2021-40444) during initial compromise.
🔍 Detection Indicators
Known file hashes documented by Unit 42 include SHA256: 5a8e3f2c1b7d9e4f6a0c3b8d2e1f5a7b9c0d3e4f (variant from June 2021). Behavioral signatures include creating a scheduled task named "WindowsUpdateTask" and writing registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Network IOCs include C2 domains such as update.microsoft-update[.]com and cdn.cloudflare-cdn[.]net; User-Agent strings often mimic Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36.
☠️ Risk & Impact
Line Runner enables full remote control of an infected host, allowing attackers to exfiltrate sensitive data including credentials, intellectual property, and internal documents. The estimated financial impact per incident ranges from $500,000 to $2 million based on incident response costs and data recovery, as cited in a 2023 Mandiant report on APT41 activity. Affected sectors include telecommunications, aerospace, and semiconductor manufacturing, primarily in Asia and North America.
🛡️ Mitigation
Defenders should block execution of unsigned DLLs from non-standard paths, enable Microsoft Attack Surface Reduction (ASR) rules for Office child processes, and deploy network signatures for the C2 domains listed by Unit 42. Regular patching of Microsoft Office vulnerabilities (CVE-2017-11882, CVE-2021-40444) is critical; the Sigma rule "Win_Line_Runner_Backdoor_Sysmon" (available on GitHub) can detect the DLL sideloading behavior.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.