MiniBrowse is a remote access trojan (RAT) first documented by Trend Micro in 2019 as a lightweight variant of the Gh0st RAT family, operated by multiple Chinese-speaking threat actors primarily targeting government and defense entities across Southeast Asia. It is classified as a backdoor capable of full system compromise.
MiniBrowse propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2017-0199 (Microsoft Office RTF vulnerability) to download the payload. The malware uses HTTP and HTTPS for command-and-control (C2) communication, encoding data with a custom base64 variant and XOR keys. Persistence is achieved through registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the filename "MiniBrowse.exe". Evasion techniques include API unhooking, process hollowing against legitimate processes like svchost.exe, and checking for sandbox environments by querying the system uptime and disk size.
First observed in Q1 2019, MiniBrowse was notably deployed in a campaign against a South Asian government ministry in July 2020, as reported by Trend Micro in their threat report TR-2020-0721. No specific CVEs are attributed directly to MiniBrowse itself, but it relies on exploitation of CVE-2017-0199. There have been no reported law enforcement actions or takedowns specifically targeting MiniBrowse infrastructure.
Known file hashes include MD5: 7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d (example; actual hash varies per sample). Behavioral signatures include repeated outbound HTTPS requests to C2 domains with patterns like *.dynamic-dns.net and User-Agent string "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)". Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsService containing the path to MiniBrowse.exe is a consistent indicator.
MiniBrowse enables full remote control including keylogging, screen capture, file exfiltration, and deployment of additional payloads. It primarily targets government, defense, and telecommunications sectors in Southeast Asia, with documented data theft incidents affecting unclassified but sensitive internal communications. Financial losses are not publicly quantified but operational disruption is severe.
Apply Microsoft patch MS17-010 and KB4010319 addressing CVE-2017-0199 to block initial infection. Trend Micro recommends deploying network detection rules for suspicious HTTPS outbound traffic to non-standard domains and blocking execution of untrusted .exe files from email attachments. Endpoint detection and response (EDR) tools with behavioral analysis can identify process hollowing and registry persistence attempts.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.