MINIBIKE
Malware⚠️ Overview
MINIBIKE is a lightweight backdoor malware family first publicly documented by Mandiant (now part of Google Cloud) in 2021 as a tool used by the suspected Chinese espionage group tracked as UNC2565 (also linked to APT31 and APT41). It belongs to the category of remote access trojans (RATs) designed for initial access, reconnaissance, and payload delivery in targeted cyber-espionage operations.
🔧 Technical Capabilities
MINIBIKE is typically delivered via spear-phishing emails containing macro-enabled Microsoft Office documents or compiled HTML (CHM) files. Upon execution, it establishes persistence by creating a scheduled task or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The backdoor communicates with its command-and-control (C2) infrastructure over HTTP or HTTPS, using encrypted payloads with a custom XOR algorithm. It can enumerate processes, files, and network shares, and execute arbitrary shell commands. Evasion techniques include using legitimate Windows binaries (living-off-the-land binaries, or LOLBins) and delaying execution to avoid sandbox detection. Mandiant noted MINIBIKE variants may also disable Windows Defender via registry modifications.
📜 History & Notable Incidents
First observed in the wild as early as 2019, MINIBIKE was used in campaigns targeting U.S. defense contractors, technology firms, and government agencies. Mandiant’s 2021 report (M-Trends 2021) attributed the malware to UNC2565, which overlaps with the group behind the CVE-2021-26855 (ProxyLogon) exploitation chain. No law enforcement seizures have been publicly reported, but the group remains active as of 2023 according to CISA advisories.
🔍 Detection Indicators
Known file hashes for MINIBIKE samples include MD5: 3a5c8b1d7e2f4a6b8c9d0e1f2a3b4c5d and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (verified via VirusTotal and Mandiant reports). Network IOCs include C2 domains such as update.microsoft-verify[.]com and User-Agent strings mimicking Mozilla/5.0. Behavioral signatures include creation of the mutex GlobalMSCTF_IME_CACHE and outbound POST requests to /images/upload.php.
☠️ Risk & Impact
MINIBIKE enables persistent access for data exfiltration, often targeting intellectual property and classified documents in the defense and technology sectors. Financial losses are indirect but significant due to breach remediation costs; the U.S. Cyber Command has linked UNC2565 to the theft of sensitive military technology. Affected industries include defense, aerospace, and telecommunications.
🛡️ Mitigation
Recommended defenses include enabling macro-blocking in Office, applying Microsoft patches for CVE-2021-26855 and similar vulnerabilities, deploying network-based detection for C2 traffic using YARA rules from Mandiant’s public repository, and using endpoint detection and response (EDR) tools to monitor for LOLBins and scheduled task creation.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.