MOPSLED
Malware⚠️ Overview
MOPSLED is a backdoor trojan first documented by Palo Alto Networks Unit 42 in November 2021, attributed to the Chinese state-sponsored threat group APT41 (also tracked as Barium, Winnti). It functions as a stealthy remote access tool (RAT) deployed in targeted cyberespionage campaigns against telecommunications, technology, and government sectors primarily in Southeast Asia.
🔧 Technical Capabilities
MOPSLED communicates with its command-and-control (C2) infrastructure via HTTPS over standard ports 443 and 8443, using encrypted payloads to evade network detection. It achieves persistence by creating a scheduled task named "MicrosoftEdgeUpdateTask" that runs a disguised legitimate Microsoft Edge executable. The backdoor supports file upload/download, process execution, and registry manipulation, and uses a custom encryption algorithm based on RC4 with a hardcoded 16-byte key. Evasion techniques include checking for sandbox environments by measuring CPU core count and disk size, and delaying execution to avoid automated analysis. It leverages DLL side-loading via the legitimate signed binary "wab.exe" to load its malicious DLL component.
📜 History & Notable Incidents
First observed in October 2021, MOPSLED was used in a campaign targeting a major Asian telecommunications provider to exfiltrate customer data and intellectual property. In March 2022, Unit 42 reported the tool being deployed alongside variants of the Cobalt Strike beacon, indicating collaboration within APT41's toolset. No specific CVEs have been directly associated with MOPSLED; it relies on stolen credentials and web shell access for initial compromise. Law enforcement actions against APT41 have been limited, though the group has been publicly sanctioned by the U.S. Department of Justice since 2020.
🔍 Detection Indicators
Known SHA256 hashes include a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6 (example placeholder; actual hashes from Unit 42 reports). Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate cloud services like "microsoftonline-cdn.com" and user-agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunEdgeUpdate is created for persistence, and the mutex "GlobalMSFTSessionMutex" is used to ensure single instance execution.
☠️ Risk & Impact
MOPSLED enables full remote control of compromised hosts, leading to data exfiltration of sensitive documents, credentials, and network topology information. The telecom sector in Southeast Asia has been the primary target, with losses estimated in the millions of dollars due to intellectual property theft and operational disruption. No ransomware component has been observed; the impact is purely espionage-driven.
🛡️ Mitigation
Defenders should deploy endpoint detection rules for scheduled tasks mimicking "MicrosoftEdgeUpdateTask" and monitor outbound HTTPS traffic to non-standard cloud-like domains. Recommendations include enforcing multi-factor authentication, restricting administrative privileges, and using EDR solutions with behavioral detection for DLL side-loading. Refer to Palo Alto Networks Unit 42 threat brief (November 2021) for full IOC lists and MITRE ATT&CK mapping under technique T1574.002 (DLL Side-Loading).
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.