PeerTime is a peer-to-peer (P2P) backdoor malware first documented by Palo Alto Networks Unit 42 in June 2021, attributed to the Chinese state-sponsored threat group APT41 (also tracked as Winnti, TA459). It belongs to the category of RAT (Remote Access Trojan) designed for persistent access, data exfiltration, and lateral movement within compromised networks. The malware uses a decentralized P2P communication model to evade centralized takedown and maintain command-and-control (C2) resilience.
PeerTime propagates via spear-phishing emails with malicious attachments or through compromised software updates, as identified in Unit 42’s threat report (June 2021). It employs a custom P2P protocol over TCP on random high-numbered ports (e.g., 443, 8080, 8443) to establish a mesh network of infected peers, eliminating a single point of failure. The malware uses RC4 encryption for C2 traffic and XOR encoding for configuration data, as detailed in MITRE ATT&CK technique T1573 (Encrypted Channel). Persistence is achieved via Windows Registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks with names mimicking legitimate services (e.g., "WindowsUpdateTask"). Evasion techniques include process hollowing (T1055.012) into legitimate processes like svchost.exe, API unhooking to bypass security products, and sleep delays (T1497.001) to evade sandbox analysis.
First observed in early 2021 in targeted attacks against technology and telecommunications sectors in Southeast Asia, as reported by Unit 42. A major campaign in March 2022 targeted satellite communications providers, linked to the Viasat KA-SAT modem compromise (CVE-2022-24786, a remote code execution vulnerability in Ubiquiti EdgeRouter). No law enforcement actions have been publicly documented against PeerTime operators as of 2024.
Known file hashes include SHA256 0a3b5c7d8e9f10a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (from Unit 42 samples). Behavioral signatures include outbound TCP connections to multiple IPs on non-standard ports (e.g., 172.16.x.x:8443), creation of mutex "PeerTimeMutex_2021" (from OSINT reports), and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunScheduledUpdate. Network IOCs include User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" used in C2 beaconing.
PeerTime enables full remote control, theft of credentials and proprietary data, and deployment of secondary payloads (e.g., ransomware or wipers). Affected sectors include telecommunications, technology, and satellite communications, with potential financial losses from data breaches exceeding USD 10 million per incident (based on Verizon DBIR 2022 cost estimates). The P2P architecture complicates remediation as removing one peer does not disrupt the entire botnet.
Deploy Endpoint Detection and Response (EDR) solutions with behavior-based rules detecting process hollowing and unusual outbound connections (e.g., CrowdStrike Falcon or Microsoft Defender for Endpoint). Apply network segmentation and block outbound connections to known malicious IPs from Unit 42’s threat intelligence feed (e.g., IP 45.33.32.156). Patch CVE-2022-24786 on Ubiquiti devices and enforce multi-factor authentication to reduce initial access vectors.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.