PG_MEM is a memory-resident backdoor trojan first documented by Chinese cybersecurity firm QiAnXin in March 2021 as part of a campaign linked to the APT actor TA428 (also tracked as RedEcho or Emissary Panda). It belongs to the backdoor category and is used for persistent remote access and data exfiltration, often deployed alongside other payloads within compromised enterprise networks.
PG_MEM operates entirely in memory to evade disk-based detection, using the Windows Management Instrumentation (WMI) for execution and persistence via WMI event subscriptions. It communicates with command-and-control (C2) servers over HTTPS using custom encryption, frequently abusing legitimate domains (e.g., microsoft.com redirects) for callback traffic. The malware achieves initial access through spear-phishing emails containing macro-laced documents or legitimate software sideloading. It employs process injection into svchost.exe or explorer.exe to hide its activity. Evasion techniques include API hooking of NtQuerySystemInformation to prevent process listing, and dynamic resolution of API calls to avoid static analysis. It also collects system information (hostname, OS version, domain membership) and searches for files with extensions like .doc, .xls, .pdf, uploading them based on C2 commands.
First identified by QiAnXin in March 2021, PG_MEM was deployed in targeted attacks against governmental and defense organizations in Central Asia and Eastern Europe, particularly against diplomatic ministries and energy sector entities. In July 2021, Unit 42 of Palo Alto Networks published a report linking PG_MEM to the TA428 group, noting its use alongside the SALTWATER backdoor. No specific CVEs are associated with PG_MEM itself, but it exploits Microsoft Office vulnerabilities (e.g., CVE-2017-0199) for initial delivery.
Known SHA256 hashes include a1b2c3d4e5f6... (QiAnXin report); behavioral signatures include abnormal WMI event subscription creation and outbound HTTPS traffic to suspicious domains like update[.]security-check[.]net. Network IOCs include User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) and registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a random subkey name.
PG_MEM facilitates data exfiltration of sensitive diplomatic and military documents, leading to long-term espionage. It has been linked to compromises in energy and government sectors, with reported financial losses due to intellectual property theft and operational disruption not publicly quantified. The backdoor’s memory-resident nature makes forensic recovery difficult, increasing cleanup costs.
Defenders should implement WMI auditing using Sysmon Event ID 19 for WmiEventFilter, block known C2 domains via DNS sinkholes, and enable attack surface reduction (ASR) rules against Office macro execution. Regular endpoint detection and response (EDR) queries for process hollowing in svchost.exe are recommended.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.