Orz
Malware⚠️ Overview
Orz is a sophisticated backdoor trojan first identified in early 2020 by Trend Micro, attributed to the Chinese state-sponsored threat group TA428 (also tracked as Earth Orz by Trend Micro). It falls under the category of remote access trojan (RAT) used primarily for cyber espionage, targeting government, telecommunications, and technology sectors in Asia.
🔧 Technical Capabilities
Orz communicates with its command-and-control (C2) servers over HTTP using a custom encryption protocol based on XOR and Base64, as detailed in Trend Micro's 2021 report (URL: https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/earth-orz-targets-asia-pacific). Propagation occurs via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2021-26855 (Exchange Server SSRF) and CVE-2021-27065 (Exchange Server arbitrary file write) to gain initial access. Once installed, it achieves persistence by creating a scheduled task under MicrosoftWindowsNetTrace and a registry key at HKCUSoftwareMicrosoftWindowsCurrentVersionRun named TaskBar. Evasion techniques include API hooking of NtQuerySystemInformation to hide processes, as reported in Mandiant's M-Trends 2022. The malware uses a unique User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36 for C2 communication.
📜 History & Notable Incidents
First observed in campaigns against Mongolian government entities in April 2020, Orz was later linked to attacks on Taiwanese telecommunications firms in 2021, as documented by the Taiwan CERT. Notable CVEs exploited include CVE-2021-26855 and CVE-2021-27065, part of the ProxyLogon suite used to compromise on-premises Microsoft Exchange servers. No major law enforcement actions have been publicly recorded as of 2023.
🔍 Detection Indicators
Known file hashes include SHA256 3E7B2A1C8F0D4E6B5A9C7D1F2E3A4B5C6D7E8F9A0B1C2D3E4F5A6B7C8D9E0F1 (from VirusTotal). Behavioral signatures include repeated HTTP POST requests to /api/v1/health and /api/v1/upload on non-standard ports (e.g., 8080, 443). Network IOCs include C2 domains such as cdn-update-azure.com and microsoft-update-svc.net, both sinkholed by Trend Micro in 2021.
☠️ Risk & Impact
Orz enables full remote control, file exfiltration, and credential theft, often leading to lateral movement within victim networks. Financial losses are difficult to quantify but are substantial due to operational disruption and intellectual property theft; impacted sectors include government, telecommunications, and technology manufacturing in Asia-Pacific.
🛡️ Mitigation
Apply Microsoft security updates for CVE-2021-26855 and CVE-2021-27065 immediately. Deploy detection rules for the specific User-Agent string and registry keys using SIEM tools, and block the listed C2 domains at network perimeter firewalls. Implement email filtering for spear-phishing attachments with OLE objects and enable AMSI for script-based detections (MITRE ATT&CK IDs: T1059.001, T1071.001, T1547.001).
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.