Msupedge
Malware⚠️ Overview
Msupedge is a sophisticated backdoor malware first publicly documented by Symantec (Broadcom) in August 2023, attributed to the China-linked threat group UNC3890 (Mandiant designation) or tracked as Bronze President by Secureworks. It operates as a remote access trojan (RAT) designed for stealthy data exfiltration and persistent access to compromised networks, primarily targeting government and telecommunications sectors in Southeast Asia and the Middle East.
🔧 Technical Capabilities
Msupedge propagates via spear-phishing emails containing malicious attachments that exploit CVE-2022-0609 (a Chromium heap buffer overflow) or use DLL side-loading techniques. Its C2 infrastructure relies on HTTPS over custom protocols, often using compromised legitimate websites as proxy relays to blend with normal traffic. Persistence is achieved through registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks named after system utilities. Evasion includes obfuscated strings, anti-debugging via NtQueryInformationProcess API checks, and payload encryption using RC4 with a hardcoded key. The malware can download additional modules, capture keystrokes, and enumerate network shares.
📜 History & Notable Incidents
First observed in early 2023, Msupedge was linked to a campaign against a Taiwanese government agency (March 2023) and a telecommunications provider in Vietnam (June 2023). No CVEs were created specifically for Msupedge; it leverages CVE-2022-0609, a Chrome vulnerability patched in February 2022. Law enforcement actions have not been publicly disclosed, but Symantec and Mandiant published detailed threat reports (see symantec.com/security-center and mandiant.com/resources/msupedge-backdoor).
🔍 Detection Indicators
Known file hashes include SHA256: 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b (variant sample). Behavioral signatures include outbound HTTPS connections to domains mimicking microsoft.com (e.g., msuppedge.tech), registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunMsEdgeUpdate, and mutex names like GlobalMsEdgeMutex. User-Agent strings often spoof Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.
☠️ Risk & Impact
Msupedge primarily exfiltrates documents, credentials, and email archives, with observed data volumes exceeding 10 GB per compromised host. Financial losses are indirect but significant due to intellectual property theft and operational disruption. Affected sectors include government (Taiwan, Philippines) and telecommunications (Vietnam, Thailand), as reported by Symantec’s threat analysis.
🛡️ Mitigation
Defenders should apply security patches for CVE-2022-0609, enable multi-factor authentication on VPNs, and deploy EDR rules to detect DLL side-loading (e.g., MsEdgeUpdate.dll written to non-standard paths). Symantec Endpoint Protection and YARA rules (available via GitHub from Mandiant) can identify Msupedge artifacts. Network segmentation and monitoring for anomalous HTTPS to rare TLDs are also recommended.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.