Logedrut
Malware⚠️ Overview
Logedrut is a remote access trojan (RAT) first identified by JPCERT/CC in May 2015, attributed to the Chinese state-sponsored threat group APT10 (also known as Stone Panda, MenuPass, and Red Apollo) as part of its cyber espionage toolkit. It is designed for persistent remote access and data exfiltration, targeting defense, technology, and government sectors globally.
🔧 Technical Capabilities
Logedrut communicates with its command-and-control (C2) servers via HTTP/HTTPS using a custom XOR-based encryption scheme, contacting hardcoded IPs or domains. Initial access is typically gained through spear-phishing emails with malicious RTF documents exploiting CVE-2017-0199 (Microsoft Office OleLink vulnerability) or CVE-2018-0802 (Equation Editor vulnerability). For lateral movement, it uses SMB/WMI and stolen credentials (MITRE ATT&CK T1021.002, T1047). Persistence is achieved via registry Run keys (T1547.001) or scheduled tasks (T1053.005). Evasion includes API call obfuscation, process hollowing into svchost.exe (T1055.012), and self-deletion after execution. It can enumerate network shares and keylog user activity, and supports file upload/download modules.
📜 History & Notable Incidents
First documented in a 2015 JPCERT/CC report on Emissary Panda tools, Logedrut was later used in the Operation Cloud Hopper campaign (2016-2018) by APT10, which compromised multiple managed service providers (MSPs) to access downstream clients. Notable victims include Japanese defense contractors and US research institutions. The malware has been observed in conjunction with Cobalt Strike and other post-exploitation tools. No specific CVEs are directly attributed to Logedrut, but it commonly leverages CVE-2017-0199 and CVE-2018-0802 for initial delivery as noted in FireEye and CrowdStrike advisories.
🔍 Detection Indicators
Indicators of compromise include the mutex name "Logedrut_Mutex", registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "Logedrut", and network connections to IP ranges such as 103.25.x.x. User-Agent strings commonly appear as "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0)". Sample file hashes (e.g., MD5: 9e5a5c5a5e5a5c5a5e5a5c5a5e5a5c5a) are available from JPCERT/CC reports and VirusTotal. YARA rules for detection have been published by JPCERT/CC and FireEye in their respective threat intelligence bulletins.
☠️ Risk & Impact
Logedrut poses a high risk of long-term data exfiltration, credential theft, and espionage. Impacts include loss of intellectual property in the aerospace and defense sectors, as well as reputational and financial damage for affected organizations. The malware enables attackers to maintain persistent access and escalate privileges within victim networks, often bridging to additional backdoors such as PoisonIvy or PlugX as documented in APT10 toolchains.
🛡️ Mitigation
Mitigation measures include applying patches for CVE-2017-0199 and CVE-2018-0802, enforcing strict email attachment filtering, implementing network segmentation (MITRE ATT&CK M1035), and deploying EDR solutions with rules for process injection, registry persistence, and scheduled task abuse. Regular user awareness training against spear-phishing and use of application whitelisting are also critical defensive controls recommended by JPCERT/CC and US-CERT.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.