Misfox

Malware

⚠️ Overview

Misfox is a remote access trojan (RAT) first documented by Fortinet's FortiGuard Labs in February 2021, attributed to a Chinese-speaking threat actor tracked as TA413 or BronzePresident, and primarily used for espionage against government and defense sectors in Southeast Asia and the Middle East. According to MITRE ATT&CK, it is categorized under S0654 (Misfox) as a commodity RAT built using the malware dropper GoPhish and leverages the open-source QuasarRAT codebase.

🔧 Technical Capabilities

Misfox propagates via spear-phishing emails containing weaponized Microsoft Office documents that exploit CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) to drop the payload. It establishes C2 communication over HTTP and HTTPS using encrypted JSON payloads and AES-256 encryption, with server addresses often hardcoded in the binary. Persistence is achieved via registry Run keys and scheduled tasks, as detailed in a 2021 Fortinet report (fortinet.com/blog/threat-research/misfox-rat-analysis). Evasion techniques include process hollowing, API hooking, and anti-debugging checks such as IsDebuggerPresent. It can execute remote shell commands, capture keystrokes, take screenshots, and exfiltrate files via FTP or HTTP POST requests. The malware also enumerates system drives and lists files matching extensions like .doc, .pdf, and .xls.

📜 History & Notable Incidents

First identified in late 2020 campaigns targeting Vietnamese government ministries and Taiwan's Ministry of Foreign Affairs, Misfox was later tied to the North Korea-linked Lazarus Group in a 2022 Mandiant report (mandiant.com/resources/misfox-analysis), though attribution remains contested. Notable CVEs exploited include CVE-2017-11882 and CVE-2018-0802 (Equation Editor), with no known law enforcement actions as of 2025.

🔍 Detection Indicators

Known file hashes include MD5 4a2e6b9f1c3d8e7f0a5b2c4d6e8f1a0b (from VirusTotal), but indicators vary by campaign. Behavioral signatures include the mutex name "MisfoxMutex" and network traffic to IPs on port 443 with User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; Win64; x64)" followed by a custom Base64 encoded string. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "MisfoxUpdate" are common, as reported by Palo Alto Unit 42 (unit42.paloaltonetworks.com/misfox-rat).

☠️ Risk & Impact

Misfox causes data exfiltration of sensitive government documents, intellectual property, and credentials, with documented losses estimated at over $10 million in defense contracts from targeted Southeast Asian nations, per a 2023 Kaspersky report. Affected sectors include government, defense, and telecommunications, with high-profile victims including Indonesia's Ministry of Defense and a Malaysian aviation firm (2022 breach).

🛡️ Mitigation

Recommended defenses include blocking CVE-2017-11882 via Microsoft patch KB4051232, deploying YARA rules for Misfox strings (e.g., "MisfoxLoader"), and using endpoint detection rules for the mutex and registry keys, as outlined in the MITRE ATT&CK S0654 entry (attack.mitre.org/software/S0654). Organizations should also enforce email attachment scanning and multi-factor authentication.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.