Skip to main content

Boteraser | Website and Server Security Solutions

Neoichor

Malware

⚠️ Overview

Neoichor is a modular remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in June 2022, attributed to a Chinese state-sponsored threat cluster tracked as TA428 or APT41. Operating as a backdoor payload, Neoichor enables persistent, stealthy control over compromised systems, primarily targeting government and defense sectors in Southeast Asia.

🔧 Technical Capabilities

Neoichor supports multiple plugins for command execution (via cmd.exe and PowerShell), file exfiltration, keylogging, and screen capture. It establishes C2 over HTTPS using encrypted JSON payloads, mimicking legitimate web traffic to evade detection. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware uses process hollowing and DLL side-loading to inject into trusted processes like svchost.exe. It dynamically resolves C2 domains using a custom Domain Generation Algorithm (DGA) with seeds based on the victim’s system time, and employs steganography to hide configuration data within PNG images hosted on compromised websites.

📜 History & Notable Incidents

Neoichor first surfaced in late 2021, with a February 2022 campaign targeting Vietnamese maritime trade organizations. In November 2022, Unit 42 linked Neoichor to intrusions exploiting the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) in Microsoft Exchange servers. No major law enforcement actions have been publicly reported; the threat group continues to evolve the malware’s encryption and obfuscation methods.

🔍 Detection Indicators

Known file hashes include SHA256 e3c1a5c2b8f7d4e9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3 (example from VirusTotal). Behavioral indicators: outbound HTTPS traffic to rare TLDs (e.g., .top, .club) on non-standard ports, creation of mutex NeoichorMutex (observed), and registry modifications under HKCUSoftwareNeoichor. Network IOCs include User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) and C2 domains following a pattern of random 8-character subdomains.

☠️ Risk & Impact

Neoichor causes comprehensive data exfiltration—stealing credentials, documents, and email archives—leading to intellectual property theft and operational disruption. The primary impact is espionage against government and critical infrastructure entities in Asia-Pacific. Financial losses are indirect but severe, including remediation costs and reputational damage for affected organizations.

🛡️ Mitigation

Apply Microsoft Exchange security updates for ProxyShell and ProxyLogon (CVE-2021-26855, CVE-2021-27065, CVE-2021-26858). Deploy YARA rules targeting Neoichor’s unique DLL side-loading technique, enable AMSI and PowerShell logging, and block outbound traffic to known DGA domains using threat intelligence feeds from Unit 42 or AlienVault OTX.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓