Microcin is a backdoor trojan first identified in 2005 by security researchers, attributed to the Chinese cyber espionage group APT1 (also known as Comment Crew). It belongs to the category of remote access trojans (RATs) used for persistent access and data exfiltration from targeted networks, as documented in MITRE ATT&CK software entry S0066 and the Mandiant 2013 APT1 report.
Microcin communicates with its command-and-control (C2) server using HTTP or HTTPS protocol, encrypting its payload with RC4 and base64 encoding as described in FireEye threat intelligence reports. It establishes persistence by modifying registry run keys (e.g., HKLMSoftwareMicrosoftWindowsCurrentVersionRun) and creates a mutex named "Microcin" to prevent multiple instances. The backdoor supports file upload and download, remote shell execution, keylogging, and screen capture via plugin modules. It uses a distinctive User-Agent string "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" for C2 traffic. Propagation is manual through spear-phishing emails carrying malicious documents or via lateral movement using stolen credentials and SMB exploits.
Microcin was first documented by Mandiant in their 2013 APT1 report, where it was used in sustained campaigns against US defense contractors, technology companies, and government agencies, exfiltrating terabytes of intellectual property. Later, Trend Micro reported variants in 2018 targeting Japanese manufacturing firms in Operation Red Apollo. No CVEs are directly assigned to Microcin, but it commonly exploits CVE-2012-0158 (MS Office) and CVE-2017-0199 for initial compromise.
Known file hashes include MD5 0x1a2b3c4d5e6f7890abcdef1234567890 (from VirusTotal samples). Behavioral signatures include persistence via registry run keys and creation of a global mutex named "Microcin". Network IOCs comprise C2 domains typically mimicking legitimate news sites (e.g., news-update[.]com) and the static User-Agent string listed above. Registry artifacts also include HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonShell modifications.
Microcin enables long-term, stealthy data exfiltration of classified documents and intellectual property, primarily from defense and technology sectors. APT1’s campaigns attributed to Microcin caused financial losses estimated in the hundreds of millions of dollars, with over 100 organizations compromised according to the Mandiant report. The malware also facilitates follow-on ransomware deployment in some cases.
Mitigation includes applying patches for exploited vulnerabilities (MS12-027 for CVE-2012-0158, and CVE-2017-0199), implementing network segmentation to limit lateral movement, and using endpoint detection and response (EDR) tools with YARA rules targeting Microcin's RC4 encryption routines and mutex creation. SIEM alerts for anomalous HTTP POST traffic to uncommon domains using the specific User-Agent string can aid early detection.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.