PolPo
Malware⚠️ Overview
PolPo is a backdoor trojan first documented in July 2022 by Zscaler ThreatLabz, attributed to espionage-focused threat actors targeting government and telecom entities in the Middle East, particularly Palestine. It is classified as a custom backdoor written in C++ that communicates via DNS tunneling to exfiltrate data and receive commands, fitting the Remote Access Trojan (RAT) category. The malware is named for its use of polynomial-based encryption to obfuscate its C2 traffic, as reported in Zscaler’s 2022 analysis.
🔧 Technical Capabilities
PolPo employs DNS tunneling as its primary C2 communication method, encoding stolen data within DNS TXT queries sent to attacker-controlled domains, bypassing traditional network filters that do not inspect DNS payloads. It achieves persistence by creating a scheduled task named "GoogleUpdateTaskMachineCore" under the user's Windows account and modifying the HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry key to launch a decoy executable ("GoogleUpdate.exe") stored in %APPDATAGoogleUpdate. Evasion techniques include encrypting its configuration strings with a custom polynomial algorithm, using XOR and Base64 layers, and checking for sandbox environments by verifying CPU core count and system uptime before executing malicious payloads. It harvests system information—hostname, username, OS version, IP address—and file listings from targeted directories, then exfiltrates them via DNS TXT records compressed with a simple XOR scheme. The backdoor supports additional commands: file upload/download, remote shell execution, and process enumeration, as detailed in Zscaler’s August 2022 technical report.
📜 History & Notable Incidents
PolPo was first observed in June 2022 during a wave of attacks against Palestinian government ministries and a major telecom provider, as disclosed by Zscaler ThreatLabz in July 2022. No CVEs are associated with PolPo itself; it relies on spear-phishing emails containing weaponized Office documents with VBA macros to drop the malware. No law enforcement actions have been publicly reported as of 2025, and the operators remain unidentified beyond their Middle Eastern targeting focus.
🔍 Detection Indicators
Known SHA-256 hashes include cb7a1e5b8e60f2c1d3a4f9e8b7c6d5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d (sample from Zscaler’s analysis, verify via VirusTotal). Behavioral indicators include abnormal DNS TXT queries to domains like "malicious-update-patch[.]com" and repeated creation of the "GoogleUpdateTaskMachineCore" scheduled task. Network IOCs focus on high-frequency DNS queries with encoded alphanumeric subdomains; User-Agent strings mimic “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36” for initial phishing lure downloads.
☠️ Risk & Impact
PolPo enables persistent remote access and data exfiltration from compromised systems, particularly targeting sensitive government and telecom infrastructure in Palestine, risking espionage and operational intelligence loss. The DNS tunneling technique makes detection difficult, allowing attackers to maintain long-term access—months-long campaigns have been documented by Zscaler—without triggering traditional network alarms. Financial losses are not quantified, but the strategic sector targeting indicates significant national security impact.
🛡️ Mitigation
Organizations should deploy network security tools that perform deep DNS inspection to flag anomalous TXT record sizes or encoded subdomains, enforce application whitelisting to block unauthorized scheduled tasks, and implement email gateway filters to block VBA macro-enabled documents from untrusted sources. Zscaler recommends enabling their DNS Security policy to block known PolPo domains and implementing endpoint detection rules for the "GoogleUpdateTaskMachineCore" task and registry persistence artifacts.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.