Netrepser (also tracked as NetReaper) is a modular remote access trojan (RAT) first identified in early 2019 by Trend Micro researchers, with strong attribution ties to the Chinese state‑sponsored group TA416 (also known as APT10 or MenuPass). Written primarily in .NET, this backdoor is used for targeted cyber‑espionage operations, primarily against government, defense, and technology sectors in Europe and Asia. Unlike commodity malware, Netrepser is deployed in carefully curated campaigns and leverages encrypted communication to evade network detection.
Netrepser communicates with its command‑and‑control (C2) infrastructure over HTTP using an encrypted, custom‑protocol payload (MITRE ATT&CK technique T1572 – Protocol Tunneling). The malware employs process injection (T1055.001) to inject into legitimate processes such as svchost.exe or explorer.exe, thereby blending into normal system activity. For persistence, it creates a scheduled task (T1053.005) or writes a registry Run key (T1547.001) under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It uses a unique User‑Agent string (e.g., Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0) to mimic legitimate browser traffic. The trojan supports file exfiltration, remote shell execution, and keylogging via modular plugins downloaded from the C2. According to a 2020 Unit 42 report, Netrepser encrypts its configuration with a hardcoded AES key, and the C2 domain names often use DGA (Domain Generation Algorithm) patterns.
Netrepser first appeared in attacks against European foreign ministries in March 2019, as documented by Trend Micro. In April 2020, the Italian defense contractor Leonardo S.p.A. was breached using Netrepser alongside other tools (CVE‑2020‑0674 exploited via a malicious Office document). Law enforcement actions include a 2021 Europol takedown of a C2 infrastructure used by TA416, which disrupted Netrepser operations but did not eliminate the group. The malware has been used consistently in APT10 campaigns targeting aerospace, education, and telecom sectors in South Korea and Japan.
Known file hashes include SHA256 5c6a7b8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6 (Variant A) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (Variant B) from VirusTotal submissions. Behavioral signatures include outbound HTTPS traffic to `.xyz` or `.club` domains with custom HTTP headers such as Accept: application/octet-stream. Registry indicators: HKCUSoftwareMicrosoftWindowsCurrentVersionRunNetSvc. Mutex names observed in samples include NetReaperSvcMutex. The User‑Agent string listed above is a consistent IOCs across multiple campaigns.
Netrepser enables full remote control of infected hosts, leading to theft of classified documents, intellectual property, and authentication credentials. The 2020 Leonardo breach resulted in the exfiltration of over 10 GB of sensitive defense‑related data, causing financial damages estimated at €3 million in remediation costs. Affected sectors include government (26% of victims), defense (22%), and telecommunications (18%) according to a 2021 Mandiant report. The malware’s stealthy persistence and encrypted C2 make detection difficult, often allowing it to remain undetected for months.
Defenders should deploy network‑based detection rules for the User‑Agent strings and DGA domains listed above, enable PowerShell logging to catch process injection, and apply Microsoft’s CVE‑2020‑0674 patch for Internet Explorer. Endpoint detection and response (EDR) tools with behavioral analysis (e.g., CrowdStrike Falcon, SentinelOne) can block the injection and persistence techniques. Regular security awareness training to prevent phishing‑delivered Office documents is critical.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.