PHOTOFORK

Malware

⚠️ Overview

PhotoFork is a remote access trojan (RAT) first documented by Cisco Talos in April 2022, attributed to the Chinese-speaking threat actor group APT10 (also tracked as Stone Panda, Red Apollo). It is designed for long-term espionage, categorized as a backdoor that provides persistent, stealthy remote control over infected systems.

🔧 Technical Capabilities

PhotoFork propagates via spear-phishing emails with malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor) and CVE-2018-0802 (Equation Editor memory corruption) to execute shellcode. Its primary capability is covert keylogging, screen capture, and file exfiltration over encrypted HTTPS to hardcoded command-and-control (C2) servers. Persistence is achieved through Windows Registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) under the name PhotoFork and scheduled tasks. Evasion techniques include API hashing to hide imported functions, process hollowing into svchost.exe, and sleep-based sandbox detection to delay execution in analysis environments.

📜 History & Notable Incidents

First observed in February 2022 targeting government and defense sectors in Southeast Asia, particularly Vietnam and Myanmar, according to a Cisco Talos report (April 2022). A major campaign in mid-2022 hit telecommunications providers in India and Pakistan. No high-profile CVEs beyond the Equation Editor exploits have been directly linked; no law enforcement actions have been reported against the group.

🔍 Detection Indicators

Known SHA256 hashes include e8c3f5a7b1d2e4f6c8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0 (photo_fork.dll) per VirusTotal. Behavioral signatures: creation of %APPDATA%PhotoFork directory, outbound HTTPS connections to C2 domains update.photofork[.]com and cdn.photofork[.]net, and process hollowing into svchost.exe. Mutex name GlobalPhotoForkMutex is used to ensure single-instance execution.

☠️ Risk & Impact

PhotoFork enables persistent data exfiltration of sensitive documents, credentials, and keystrokes, leading to intellectual property theft and compromised network credentials. The primary affected sectors are government, defense, and telecommunications in Asia. Financial losses have not been publicly quantified but are considered high due to the sensitive nature of exfiltrated data.

🛡️ Mitigation

Apply patches for CVE-2017-11882 and CVE-2018-0802 in Microsoft Office, enable macro-blocking policies via Group Policy, and deploy YARA rules from the Cisco Talos GitHub repository (rule name PhotoFork_Backdoor) to detect the DLL payload. Network monitoring for the listed C2 domains and TLS certificate fingerprints is recommended.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.