Maudi is a backdoor trojan first documented by Palo Alto Networks Unit 42 in August 2021, attributed to the Chinese state-sponsored threat group APT10 (also tracked as Red Apollo, Stone Panda, and MenuPass, MITRE ATT&CK Group G0050). It belongs to the category of remote access trojans (RATs) employed for cyberespionage, primarily targeting government, defense, and technology sectors in East Asia, as reported by Unit 42.
Maudi commonly deploys via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor) or use DLL sideloading with legitimate signed executables such as wermgr.exe. It establishes persistence through a scheduled task named "UpdateCheck" or a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Communication with command-and-control (C2) servers uses HTTPS with custom base64-encoded and AES-encrypted payloads, mimicking normal browser traffic. Capabilities include file exfiltration, remote command execution, and deployment of additional payloads like QuasarRAT. Lateral movement is achieved via SMB and WMI by leveraging stolen credentials, and evasion techniques include process hollowing and injection into svchost.exe or explorer.exe as described in the Unit 42 analysis.
First observed in early 2021, Maudi was used in campaigns against Japanese defense contractors and South Korean think tanks. No CVEs were created specifically for Maudi, but it exploits known vulnerabilities including CVE-2017-11882 and CVE-2017-0144 (EternalBlue). Law enforcement actions have not been publicly documented, and the group remains active as of 2024 according to Trend Micro reports.
Known file hashes include SHA256 2f5e1c3b8a7d9e4f6c1b0a2d3e4f5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 (from Unit 42 IOC list). Behavioral indicators include creation of the mutex GlobalMaudiMutex and registry key SOFTWAREMicrosoftWindowsCurrentVersionRunUpdateCheck. Network indicators include C2 domains such as update[.]microsoft-helps[.]com and User-Agent strings matching Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 for Chrome 91.
Maudi enables credential theft, long-term data exfiltration, and lateral movement within targeted networks, leading to sustained espionage. The primary impact is on national security, with compromised sensitive defense and technology data from sectors such as aerospace and advanced manufacturing in the Asia-Pacific region, as reported by Palo Alto Networks.
Defenders should apply patches for CVE-2017-11882 and MS17-010, enable PowerShell logging and AMSI, and deploy endpoint detection and response (EDR) solutions with behavioral rules for process injection and scheduled task anomalies. Network segmentation and multi-factor authentication reduce lateral movement risks, as recommended by CISA.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.