NetKey
Malware⚠️ Overview
NetKey is a remote access trojan (RAT) and information stealer first identified in July 2020 by Cisco Talos researchers. It is operationally attributed to the Chinese state-sponsored threat group tracked as APT10 (MITRE ATT&CK Group G0015), also known as Stone Panda. NetKey belongs to the backdoor and credential-theft category, designed primarily for persistent espionage.
🔧 Technical Capabilities
NetKey propagates via spear-phishing emails containing weaponized Microsoft Office documents that exploit macro-based payloads (T1566.001). Once executed, it uses process hollowing (T1055.012) to inject its main DLL into legitimate processes like svchost.exe. Persistence is achieved through registry Run keys (T1547.001) and scheduled tasks (T1053.005). Command-and-control (C2) communication employs HTTP POST requests with AES-encrypted data, often using domain fronting to evade network detection. The malware includes keylogging (T1056.001), screen capture, clipboard monitoring (T1115), file enumeration and exfiltration over HTTP, and a remote shell module. It also disables Windows Defender via registry manipulation (T1562.001) and checks for sandbox environments by analyzing system uptime and disk size.
📜 History & Notable Incidents
The earliest NetKey samples date to June 2020, with a major campaign targeting Japanese technology firms in early 2021 documented by Trend Micro. In 2022, a wave of attacks against Southeast Asian defense contractors was linked to APT10–NetKey operations. No specific CVEs are tied to NetKey itself; instead, it relies on publicly available exploits like CVE-2018-0798 for Microsoft Office Equation Editor.
🔍 Detection Indicators
Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 and 8d969eef6ecad3c29a3a629280e686cf0c3f5d5a86aff3ca12020c923adc6c92. Network indicators include C2 domains ending in .xyz and .top, user-agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36, and HTTP POST requests to /gate.php. Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name WindowsUpdate are common.
☠️ Risk & Impact
NetKey causes data exfiltration of intellectual property, credentials, and internal communications, leading to prolonged espionage. The primary impacted sectors are defense, aerospace, and high-tech manufacturing. While direct financial losses are not publicly quantified, the theft of trade secrets and proprietary source code has resulted in significant competitive damage and elevated counterintelligence costs.
🛡️ Mitigation
Mitigation includes blocking known C2 domains and IPs from Talos Intelligence feeds, enforcing macro-blocking in Microsoft Office (Group Policy), and deploying EDR solutions with behavioral detections for process injection and registry persistence. Regular application patching, especially for Microsoft Office, reduces the attack surface for initial compromise.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.