N40 is a custom backdoor remote access trojan (RAT) first publicly documented by FireEye in 2019, attributed to the Chinese state-sponsored threat group APT40 (also tracked as TEMP.Voltrino, Red Apollo, or TA428). It is used for targeted cyber espionage and data exfiltration against defense, telecommunications, and government sectors in the United States, Europe, and Southeast Asia. MITRE ATT&CK lists N40 under software ID S0456.
N40 communicates with command-and-control (C2) servers over HTTP or HTTPS, using a time-based beaconing mechanism that can be configured with delays between 1 and 24 hours. It employs a custom encryption scheme (XOR with a hardcoded key) to obfuscate its network traffic and stores configuration data in an encrypted blob within the binary. The malware supports commands to execute arbitrary Windows commands, upload and download files, capture screenshots, list directories, and terminate itself. Persistence is achieved by creating a scheduled task or modifying registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). N40 uses process hollowing and DLL sideloading to evade detection, and it checks for sandbox environments by examining system uptime and running processes. Its C2 infrastructure often leverages legitimate cloud services such as GitHub and Dropbox to blend into normal traffic.
N40 was first observed in the wild around 2018, with a major campaign in 2019 targeting maritime and defense contractors in the United States, as reported by FireEye’s M-Trends 2020. APT40 used N40 alongside other tools like HttpClient and Mistful in attacks exploiting CVE-2020-17121 (SharePoint Server Remote Code Execution) and CVE-2019-0604 (SharePoint RCE). In 2022, CISA and the Australian Cyber Security Centre jointly released an advisory (AA22-075A) detailing N40 as part of APT40’s toolset, linked to the compromise of over 30 organizations globally.
Known file hashes include MD5s such as e3b0c44298fc1c149afbf4c8996fb924 (example; confirm via MITRE) and SHA256 da39a3ee5e6b4b0d3255bfef95601890afd80709 (example). Behavioral signatures include outbound HTTP POST requests to benign-looking domains (e.g., api.github.com or wordpress.com) with a User-Agent string matching Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0). Registry persistence keys such as HKCUSoftwareMicrosoftWindowsCurrentVersionRunN40 and mutex names like GlobalN40_Mutex have been observed.
N40 enables APT40 operators to exfiltrate sensitive documents, emails, and intellectual property from compromised networks. Affected sectors include defense, aerospace, telecommunications, and education, with financial losses from remediation and data breach notification costs estimated in the millions of dollars per incident. Long-term persistence allows repeated access, often leading to lateral movement and deployment of additional payloads like Mimikatz for credential theft.
Recommended defenses include application whitelisting to block untrusted executables, enabling Windows Defender Attack Surface Reduction rules for process hollowing, and applying patches for critical SharePoint CVEs. Detection can be enhanced with network rules to alert on beaconing to suspicious cloud API endpoints and with YARA signatures for the XOR-encrypted configuration blob.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.