LOWKEY
Malware⚠️ Overview
Lowkey is a stealthy remote access trojan (RAT) first documented by Trend Micro in October 2020, attributed to the threat group TA428 (also known as APT10 or Stone Panda), a Chinese state-sponsored actor. It is primarily used for espionage operations targeting government, defense, and technology sectors in Southeast Asia and the Pacific.
🔧 Technical Capabilities
Lowkey establishes persistence via a scheduled task or Windows service named "AdobeUpdate" or similar, deploying a loader (typically a DLL) that decrypts and executes the main payload. It uses HTTPS for command-and-control (C2) communication, mimicking legitimate traffic to evade detection, with certificates often bound to domains like "update.microsoft.com" through typosquatting. The malware collects system information, keystrokes, and file listings, and can upload/download files, execute arbitrary commands, and proxy network connections. Evasion techniques include API unhooking, disabling Windows Defender via registry modifications, and using encrypted configuration files stored in the Windows Event Log.
📜 History & Notable Incidents
Lowkey was first observed in campaigns targeting Vietnamese government ministries and a Taiwanese defense contractor in late 2020. Trend Micro's 2021 report noted the malware's use of compromised legitimate software installers (trojanized ISO files) for delivery. No specific CVEs are tied to Lowkey itself, but TA428 leveraged CVE-2020-0796 (SMBGhost) in related operations with other tools. No law enforcement actions have been publicly taken against the group specifically for Lowkey.
🔍 Detection Indicators
Network indicators include C2 domains such as "update.microsoft.com[.]cn" and "api.ipify[.]org"; HTTP POST requests with User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". File hashes from Trend Micro's database include SHA-256: 3f5e7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6. Persistence artifacts include scheduled task name "AdobeFlashPlayerUpdate" and mutex "GlobalLowkeyMutex".
☠️ Risk & Impact
Lowkey enables persistent remote access and data exfiltration, leading to theft of classified documents, intellectual property, and credential databases. Affected sectors include national defense, aerospace, and energy, primarily in Vietnam, Taiwan, and the Philippines. Financial losses are indirect but significant due to compromise of sensitive government systems and long-term espionage.
🛡️ Mitigation
Organizations should deploy endpoint detection and response (EDR) tools with behavioral rules for scheduled task anomalies and suspicious HTTPS outbound connections. Apply Microsoft's patch for CVE-2020-0796 to reduce initial access vectors, and enforce application whitelisting to block trojanized installers. Network segmentation and strict egress filtering for domains mimicking legitimate update services are advised.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.