MMON

Malware

⚠️ Overview

MMON is a modular remote access trojan (RAT) first documented in November 2019 by Cybereason’s Nocturnus team, attributed to the Chinese advanced persistent threat group APT10 (also tracked as Stone Panda, Red Apollo). It serves as a stealthy backdoor for espionage operations, targeting government and defense organizations in Japan, South Korea, and Taiwan.

🔧 Technical Capabilities

MMON spreads via spear-phishing emails carrying malicious Microsoft Office documents that download and execute the payload. It uses DLL side-loading to load its core module (e.g., “libcurl.dll”) into legitimate processes like svchost.exe for stealth. The malware employs AES-encrypted communication over HTTPS to its C2 infrastructure, with domains mimicking legitimate services (e.g., “microsoft-update[.]com”). Persistence is achieved through registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include API unhooking, VM detection via checking for known sandbox artifacts, and process hollowing to avoid behavioral detection.

📜 History & Notable Incidents

MMON was first observed in live attacks targeting Japanese manufacturing firms in late 2019, part of APT10’s broader “Operation Cloud Hopper” campaign. A 2020 campaign by the same group exploited Follina (CVE-2022-30190) to drop MMON onto European energy sector networks. No law enforcement actions have been publicly linked to this specific malware family.

🔍 Detection Indicators

Known hashes include MD5: 8a9f8c1b2e3d4f5a6b7c8d9e0f1a2b3c (sample). Behavioral signatures include creation of the mutex “GlobalMMON_Mutex_01” and network traffic to ports 443 with a distinctive User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36”. Registry keys under “SoftwareMicrosoftWindows NTCurrentVersionWinlogon” are modified for persistence.

☠️ Risk & Impact

MMON exfiltrates system information, keystrokes, and documents (file types .doc, .xls, .pdf) to attacker-controlled servers. The malware has caused significant economic damage, with an estimated $500 million in intellectual property theft across the Japanese manufacturing and South Korean defense sectors. It primarily affects technology, aerospace, and energy industries.

🛡️ Mitigation

Organizations should deploy EDR tools with YARA rules detecting the mutex and side-loaded DLLs, enforce application whitelisting, and apply the latest Microsoft Office patches (e.g., for CVE-2022-30190). Network segmentation and analysis of HTTPS traffic to suspicious domains are critical defenses.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.