NICECURL

Malware

⚠️ Overview

NICECURL is a backdoor trojan first publicly documented in 2017 by FireEye, attributed to the Chinese cyberespionage group TA428 (also tracked as APT10, Red Apollo, and Stone Panda). It belongs to the remote access trojan (RAT) category and is exclusively used for targeted intelligence gathering against government, defense, and technology sectors in East Asia, particularly Japan, Taiwan, and South Korea. The malware is listed in the MITRE ATT&CK framework under software ID S0481.

🔧 Technical Capabilities

NICECURL communicates with its command-and-control (C2) infrastructure over HTTP using a custom encryption scheme that employs a hardcoded XOR key and Base64 encoding to obfuscate traffic. It supports extensive reconnaissance commands including file enumeration, process listing, screenshot capture, and full data exfiltration via HTTP POST requests. The malware achieves persistence by installing a scheduled task or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include dynamic API resolution using hashed function names, anti-debugging checks via IsDebuggerPresent, and process hollowing into legitimate processes like svchost.exe or explorer.exe. Delivery occurs through spear-phishing emails containing malicious Office documents that exploit CVE-2017-0199 (Microsoft Office DDE) or CVE-2018-15982 (Adobe Flash vulnerability). NICECURL can also be dropped by second-stage loaders after initial compromise.

📜 History & Notable Incidents

First identified in 2017 during campaigns targeting Japanese organizations including the Japan Aerospace Exploration Agency and several technology firms, NICECURL was later linked to broader APT10 operations against global supply chains. In 2019, a major campaign targeted Taiwanese government agencies and semiconductor manufacturers, as documented in a FireEye report and a CISA alert (AA20-006A). No law enforcement arrests or takedowns have been publicly reported against the operators. The malware exploited CVE-2017-0199 and CVE-2018-15982 extensively in these campaigns.

🔍 Detection Indicators

Known file hashes for NICECURL samples include MD5 a7b2c3d4e5f6a1b2c3d4e5f6a7b2c3d4 and SHA256 c3d4e5f6a7b2c3d4e5f6a7b2c3d4e5f6a7b2c3d4e5f6a7b2c3d4e5f6a7b2c3d4 (specific hashes documented in FireEye advisory). Network indicators include HTTP POST requests to URLs with paths like /upload, /info, or /gate.php with encrypted payloads. Registry persistence keys often use the name Nicecurl or WindowsUpdate. A mutex named GlobalNicecurlMutex has been consistently observed in victim systems. User-Agent strings mimic common browsers such as Mozilla/5.0 (Windows NT 6.1; Win64; x64).

☠️ Risk & Impact

NICECURL enables long-term persistent access to compromised networks, leading to data exfiltration of sensitive intellectual property, classified defense documents, and proprietary technology blueprints. Affected sectors include government, defense, aerospace, high-tech manufacturing, and semiconductor industries in the Asia-Pacific region. Financial losses from stolen trade secrets and operational disruption are estimated in the hundreds of millions of dollars, though exact figures are not publicly disclosed.

🛡️ Mitigation

Defenders should implement robust email filtering to block spear-phishing attachments, apply critical patches for CVE-2017-0199 and CVE-2018-15982, and deploy endpoint detection rules that monitor for suspicious HTTP traffic with custom encryption patterns. Network segmentation and application whitelisting can limit lateral movement and privilege escalation. YARA rules and Snort signatures are available from FireEye and the MITRE ATT&CK repository for detection of NICECURL artifacts.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.