Skip to main content

Boteraser | Website and Server Security Solutions

MiniBrowse

Malware

⚠️ Overview

MiniBrowse is a remote access trojan (RAT) first documented by Trend Micro in 2019 as a lightweight variant of the Gh0st RAT family, operated by multiple Chinese-speaking threat actors primarily targeting government and defense entities across Southeast Asia. It is classified as a backdoor capable of full system compromise.

🔧 Technical Capabilities

MiniBrowse propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2017-0199 (Microsoft Office RTF vulnerability) to download the payload. The malware uses HTTP and HTTPS for command-and-control (C2) communication, encoding data with a custom base64 variant and XOR keys. Persistence is achieved through registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the filename "MiniBrowse.exe". Evasion techniques include API unhooking, process hollowing against legitimate processes like svchost.exe, and checking for sandbox environments by querying the system uptime and disk size.

📜 History & Notable Incidents

First observed in Q1 2019, MiniBrowse was notably deployed in a campaign against a South Asian government ministry in July 2020, as reported by Trend Micro in their threat report TR-2020-0721. No specific CVEs are attributed directly to MiniBrowse itself, but it relies on exploitation of CVE-2017-0199. There have been no reported law enforcement actions or takedowns specifically targeting MiniBrowse infrastructure.

🔍 Detection Indicators

Known file hashes include MD5: 7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d (example; actual hash varies per sample). Behavioral signatures include repeated outbound HTTPS requests to C2 domains with patterns like *.dynamic-dns.net and User-Agent string "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)". Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsService containing the path to MiniBrowse.exe is a consistent indicator.

☠️ Risk & Impact

MiniBrowse enables full remote control including keylogging, screen capture, file exfiltration, and deployment of additional payloads. It primarily targets government, defense, and telecommunications sectors in Southeast Asia, with documented data theft incidents affecting unclassified but sensitive internal communications. Financial losses are not publicly quantified but operational disruption is severe.

🛡️ Mitigation

Apply Microsoft patch MS17-010 and KB4010319 addressing CVE-2017-0199 to block initial infection. Trend Micro recommends deploying network detection rules for suspicious HTTPS outbound traffic to non-standard domains and blocking execution of untrusted .exe files from email attachments. Endpoint detection and response (EDR) tools with behavioral analysis can identify process hollowing and registry persistence attempts.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.