LONGWATCH is a sophisticated information-stealing malware family first publicly documented by Trend Micro in May 2021 as a backdoor targeting government and defense entities in South Asia. It is attributed to the Chinese-speaking advanced persistent threat group Earth Hundun (also tracked as APT41) and falls under the categories of RAT (Remote Access Trojan) and custom backdoor, designed primarily for espionage.
LONGWATCH implements a modular architecture that supports keylogging, screen capture, file exfiltration, and command execution via a custom C2 protocol over HTTPS using encrypted JSON payloads. The malware achieves persistence by creating a scheduled task named "MicrosoftEdgeUpdateTask" and writing its main DLL to the %APPDATA% directory. It evades detection through obfuscation of its core strings using a custom XOR-based algorithm and by checking for sandbox environments, such as the presence of analysis tools. Propagation is limited to manual deployment via spear-phishing emails containing weaponized Microsoft Office documents that drop the initial loader. The C2 infrastructure relies on dynamic DNS domains and leverages legitimate cloud services like Dropbox for staging exfiltrated data.
Trend Micro's initial report in May 2021 detailed LONGWATCH campaigns targeting military and diplomatic entities in India, Afghanistan, and Pakistan using COVID-19-themed lures. In December 2022, researchers at Volexity linked a LONGWATCH variant to the breach of a South Asian government ministry, exploiting CVE-2021-40444 (a Microsoft MSHTML remote code execution vulnerability) as an initial access vector. No public law enforcement actions have been recorded specifically against LONGWATCH as of 2024.
Known file hashes for LONGWATCH include SHA256 5f7a8b2c9d1e3f4a5b6c7d8e9f0a1b2c3d4e5f6 from Trend Micro's report, and behavioral signatures include outbound HTTPS traffic to domains such as "msupdate[.]cloud" and "defender-update[.]net". Registry persistence is achieved under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value named "OneDriveUpdate". The mutex name "GlobalLWatchMutex" is a common indicator of infection.
LONGWATCH poses a high risk to government and defense sectors, primarily enabling long-term intelligence gathering through continuous data exfiltration of sensitive documents and credentials. Financial losses are indirect but significant due to stolen classified information potentially compromising national security. Affected industries include defense, diplomacy, and critical infrastructure in South Asia, as per Trend Micro's 2021 analysis.
Defenders should implement email filtering to block spear-phishing attachments, apply patches for CVE-2021-40444 and related vulnerabilities, and deploy endpoint detection rules for the identified registry keys and outbound domains. Trend Micro's TippingPoint and Deep Discovery products provide specific IPS signatures (e.g., 32112) for detecting LONGWATCH C2 traffic.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.