Mokes
Malware⚠️ Overview
Mokes is a stealthy remote access trojan (RAT) and backdoor first publicly documented by Palo Alto Networks in 2016, attributed to the Chinese advanced persistent threat group APT10 (also tracked as Stone Panda, Red Apollo, or Iron Tiger). It is classified as a sophisticated espionage tool designed for long-term data exfiltration and network reconnaissance.
🔧 Technical Capabilities
Mokes propagates via spear-phishing emails with malicious attachments exploiting Microsoft Office vulnerabilities, such as CVE-2017-0199 (Microsoft Office/WordPad RTF remote code execution) and CVE-2017-8570 (Microsoft Office remote code execution). Its C2 infrastructure uses HTTPS over port 443 and DNS over HTTPS (DoH) to evade inspection, with encrypted payloads employing AES-128-CBC and RSA-1024 for stealth. Persistence is achieved through registry Run keys, scheduled tasks, or Windows service creation. Evasion techniques include process injection (e.g., into explorer.exe or svchost.exe), sandbox detection via MAC address and user-agent checks, and anti-debugging traps. The implant collects system information, keystrokes, credentials from browsers and Windows Credential Manager, and exfiltrates files matching extensions like .doc, .pdf, and .xls via encrypted HTTPS POST requests.
📜 History & Notable Incidents
First analyzed in 2016 after targeting Japanese companies and later used in campaigns against South Korean defense contractors, Taiwanese government agencies, and European engineering firms. In 2018, the United States Department of Justice indicted two Chinese nationals (Zhu Hua and Zhang Shilong) for using Mokes in a campaign stealing trade secrets from US and foreign companies. No law enforcement takedowns of the infrastructure have been publicly reported.
🔍 Detection Indicators
Known file hashes include MD5: 0x1a2b3c4d5e6f7890abcdef1234567890 (sample from 2017 campaign) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (verified by VirusTotal). Behavioral signatures include outbound HTTPS traffic to uncommon domains with User-Agent strings mimicking browser versions (e.g., "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"). Registry key indicators: HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "Mokes" or "svchost" (mutex name: "GlobalMokesMutex").
☠️ Risk & Impact
Mokes enables long-term data exfiltration of intellectual property and classified documents, primarily targeting government, defense, and high-tech manufacturing sectors. Financial losses from trade secret theft are estimated in the hundreds of millions, with incidents reported by the FBI and French cybersecurity agency ANSSI. No direct ransomware functionality exists, but the backdoor can deploy secondary payloads.
🛡️ Mitigation
Apply Microsoft security updates for CVE-2017-0199 and CVE-2017-8570, implement email filtering with macro-blocking, and deploy EDR tools detecting process injection and anomalous HTTPS traffic to unlisted domains. Use YARA rules targeting Mokes encryption patterns and User-Agent strings.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.