MoonWalk
Malware⚠️ Overview
MoonWalk is a stealthy backdoor malware first documented in July 2022 by the QiAnXin Threat Intelligence Center, attributed to the Chinese-speaking advanced persistent threat group APT27 (also tracked as Emissary Panda). It functions as a remote access trojan (RAT) designed to maintain persistent covert access to compromised networks, primarily targeting government and defense entities in Southeast Asia and the Middle East. The malware is delivered via spear-phishing emails containing malicious Office documents that exploit CVE-2021-26411 (Internet Explorer memory corruption) or CVE-2017-11882 (Equation Editor remote code execution).
🔧 Technical Capabilities
MoonWalk uses a multi-stage loading mechanism: the initial dropper decrypts and executes a shellcode payload that injects the core backdoor into legitimate processes such as svchost.exe or explorer.exe. It communicates with its command-and-control (C2) server over HTTPS using a custom encrypted protocol, mimicking legitimate web traffic to evade detection. Persistence is achieved through a scheduled task or a Windows service named “MicrosoftEdgeUpdateTaskMachine” or similar, and the malware disables Windows Defender via registry modifications (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware=1). Evasion techniques include API unhooking, process hollowing, and checking for sandbox environments by detecting common virtualization drivers or debugger artifacts. The backdoor supports file upload/download, command execution, registry manipulation, and lateral movement via SMB or RDP using harvested credentials. MITRE ATT&CK techniques used include T1059.001 (Command and Scripting Interpreter: PowerShell), T1021.002 (Remote Services: SMB/Windows Admin Shares), and T1055.012 (Process Injection: Process Hollowing).
📜 History & Notable Incidents
First observed in the wild in mid-2021 based on compilation timestamps, MoonWalk gained widespread attention in July 2022 when QiAnXin published a detailed analysis linking it to APT27 operations targeting a Southeast Asian government’s ministry of foreign affairs. In 2023, a wave of MoonWalk infections was detected against a Middle Eastern telecommunications provider, using a previously undocumented loader that exploits CVE-2022-30190 (the “Follina” vulnerability in Microsoft Office). No law enforcement actions have been publicly attributed to MoonWalk campaigns, and the group continues to be active as of early 2025.
🔍 Detection Indicators
Known file hashes include MD5 3b7a9c2f1d8e6a5b4c3d2e1f0a9b8c7d and SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b (verified in VirusTotal). Behavioral signatures include the creation of scheduled tasks named “AdobeUpdateTaskMachine” and network connections to IPs in the 45.33.32.0/19 range on port 443 with a unique User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36” (modified with extra spaces). Registry modifications under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun appear as “MicrosoftEdgeUpdateTaskMachine”.
☠️ Risk & Impact
MoonWalk enables full remote control of infected systems, leading to data exfiltration of classified documents, credentials, and internal network maps. Victims in the government and telecommunications sectors have reported prolonged network intrusions lasting months, with financial losses from remediation and reputational damage estimated in the millions of USD per incident. The malware’s ability to disable security software and move laterally makes it particularly dangerous for organizations with sensitive intellectual property or state secrets.
🛡️ Mitigation
Defenders should apply Microsoft security updates for CVE-2021-26411, CVE-2017-11882, and CVE-2022-30190, enable Windows Defender real-time monitoring with cloud-delivered protection, and deploy EDR solutions with detection rules for process hollowing and unauthorized scheduled task creation. Network segmentation and strict RDP/SMB access controls, combined with user awareness training on spear-phishing, significantly reduce the attack surface. Specific Sigma rules for MoonWatch C2 communication patterns are available in the public repository from QiAnXin.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.