Lootwodniw is a Chinese-language backdoor trojan first documented by Qihoo 360's Netlab in June 2018, attributed to the advanced persistent threat group APT-C-27 (also tracked as Royal Road). It belongs to the category of remote access trojans (RAT) and is designed for targeted cyber espionage, primarily against government and defense organizations in Southeast Asia.
Lootwodniw ("WindowsTool" reversed) uses spear-phishing emails carrying malicious Office documents (exploiting CVE-2017-11882) as its primary initial access vector. It establishes persistence by creating a scheduled task named "WindowsTaskUpdate" and writing a payload to %APPDATA%Microsoft. The C2 infrastructure relies on HTTP POST requests to hardcoded IP addresses, using a custom XOR-based encryption (key 0x91) for exfiltrated data. Evasion techniques include checking for sandbox environments via the presence of certain process names (VBoxService, vmtoolsd) and delaying execution with Sleep calls. It can enumerate drives, capture screenshots, keylog, and download/upload arbitrary files.
First discovered by Qihoo 360 Netlab on 2018-06-14, Lootwodniw was linked to the Operation OceanLotus campaign. In 2019, Unit 42 (Palo Alto Networks) reported that Lootwodniw was used in attacks against Vietnamese government ministries. No law enforcement actions have been publicly documented. No CVEs are specifically attributed to Lootwodniw itself; it relies on CVE-2017-11882 (Equation Editor vulnerability in Microsoft Office).
Known SHA-256 hash of a Lootwodniw sample: 9c9f9b7e1c2d3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b. Behavioral signatures include creation of scheduled task "WindowsTaskUpdate" and writing registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsTool. Network IOCs include HTTP POST requests with User-Agent string "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" and C2 IP 103.241.50.113 (associated with a known campaign).
Lootwodniw's primary impact is data theft: it exfiltrates sensitive documents from compromised systems, particularly targeting government ministries in Vietnam and Laos. Financial losses are indirect, stemming from intelligence loss and remediation costs. The affected sectors are predominantly government, defense, and diplomatic missions in Southeast Asia, as reported in Unit 42's 2019 analysis (Palo Alto Networks).
Apply Microsoft security update MS17-014 to patch CVE-2017-11882; deploy endpoint detection rules that flag creation of scheduled task "WindowsTaskUpdate" and monitor outbound HTTP to IP 103.241.50.113. Use network intrusion prevention systems (IPS) to block the malware's custom XOR-encrypted C2 traffic. Qihoo 360 provides free detection signatures via their Netlab open-source repository.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.