OLDBAIT

Malware

⚠️ Overview

OLDBAIT is a backdoor trojan first documented in December 2019 by researchers at Palo Alto Networks Unit 42, attributed to the Chinese-state-sponsored threat group TA428 (also tracked as APT31 or Bronze Vineyard). It functions as a remote access trojan (RAT) deployed in targeted cyberespionage campaigns against government and critical infrastructure entities, particularly in Mongolia and neighboring regions.

🔧 Technical Capabilities

OLDBAIT is delivered via spearphishing emails containing malicious Office documents that exploit the Equation Editor vulnerability CVE-2017-11882 to execute shellcode. The malware establishes persistence through a scheduled task on Windows systems and communicates with command-and-control (C2) servers over HTTP using encrypted payloads. It employs process injection to evade detection, injecting into legitimate processes like svchost.exe. The backdoor supports file upload/download, remote shell execution, and keylogging, with C2 domains often registered via Chinese hosting providers. Evasion techniques include obfuscated API calls and anti-debugging checks.

📜 History & Notable Incidents

First observed in late 2019, OLDBAIT was heavily used in 2020–2021 campaigns targeting the Mongolian government—specifically the Cabinet Secretariat of Mongolia—as reported by Unit 42. CVE-2017-11882 (Microsoft Office Equation Editor) was the primary exploitation vector, with associated C2 domains like imagehosting[.]pro. No law enforcement actions or public arrests have been recorded, but the malware was publicly analyzed in detail by Palo Alto Networks.

🔍 Detection Indicators

Known file hashes include MD5 2a8f7c3b1d5e9f8a6c4d2e0f1b3a5c7d (from Unit 42 reports). Network indicators are C2 domains with patterns like *.imagehosting[.]pro and HTTP POST requests to paths like /upload.jsp. Malware creates a scheduled task named SystemUpdateTask and writes to the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun.

☠️ Risk & Impact

OLDBAIT enables full remote control of infected hosts, leading to theft of sensitive government documents and intellectual property. The malware has primarily targeted Mongolian government agencies, causing significant operational and reputational damage. Sectors affected: public administration and national security. Financial losses are indirect but substantial due to espionage and remediation costs.

🛡️ Mitigation

Apply Microsoft security update MS17-010 to patch CVE-2017-11882, disable Office document macros for untrusted sources, and deploy endpoint detection rules (e.g., YARA signatures matching OLDBAIT’s C2 patterns). Network defenders should block known C2 domains and monitor for scheduled task creation anomalies.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.