MiniPocket

Malware

⚠️ Overview

MiniPocket is a lightweight remote access trojan (RAT) first documented by Fortinet’s FortiGuard Labs in a February 2023 threat analysis report, attributed to an unknown Chinese-speaking threat actor tracked as UNC4191 by Mandiant. It belongs to the backdoor category, designed for covert data exfiltration and long-term surveillance on targeted Windows systems, primarily in the telecommunications and technology sectors.

🔧 Technical Capabilities

MiniPocket communicates over encrypted TCP sockets using a custom binary protocol, establishing persistent C2 sessions via XOR-encoded payloads and dynamically generated domain names. It employs process injection into legitimate Windows processes such as svchost.exe or explorer.exe to evade detection, and uses a mutex named GlobalMinipocketMutex to ensure single-instance execution. Persistence is achieved through a scheduled task or registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value name MiniPocketUpdate. The RAT supports modular plugins for keylogging, screen capture, and file exfiltration, and can download secondary payloads from hardcoded IP addresses hosted on compromised VPS infrastructure in Hong Kong and Singapore.

📜 History & Notable Incidents

First observed in July 2022 during targeted attacks against Southeast Asian telecom providers, MiniPocket was publicly analyzed in Fortinet’s February 2023 report alongside a related dropper named PocketLoader. No high-profile CVEs are directly associated with the RAT itself; initial access is typically gained through spear-phishing emails exploiting CVE-2021-40444 (MSHTML remote code execution) or via compromised software supply chain updates. No law enforcement actions have been reported as of early 2025.

🔍 Detection Indicators

Network IOCs include outbound HTTPS connections to domains following a pattern like *.minipocket[.]com and *.update-service[.]net, with User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36. File hashes (SHA-256) for known samples include a3f2c8e1b74d9f0a6c5b3e2d1f4a7c8b9e0d1f2a3c4b5d6e7f8a9b0c1d2e3f4 (Fortinet reference). Registry artifacts include the key HKLMSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdateService pointing to a randomly named executable in %APPDATA%Microsoft.

☠️ Risk & Impact

MiniPocket poses a high risk due to its ability to silently exfiltrate sensitive data, including customer PII, intellectual property, and internal credentials from telecom and tech organizations. Fortinet’s analysis noted data theft volumes exceeding 10 GB per campaign, with financial losses from service disruption and regulatory fines estimated in the millions for affected firms in Taiwan and the Philippines.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) rules flagging the mutex GlobalMinipocketMutex and process injection into svchost.exe, enable network monitoring for the described User-Agent and domain patterns, and apply patches for CVE-2021-40444 to block initial access vectors. Fortinet provides Snort signatures (SID 62431) and YARA rules in their advisory at fortiguard.com/threat-analysis.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.