ProjectWood
Malware⚠️ Overview
ProjectWood is a backdoor trojan first documented by Trend Micro in April 2022, attributed to the Chinese cyber-espionage group Earth Berberoka (also tracked as APT41 or Winnti Group). It is categorized as a remote access trojan (RAT) used for targeted data exfiltration and persistent surveillance, primarily against government agencies and telecommunications firms in Southeast Asia. The malware is part of a larger toolkit known as the Peony campaign, which also includes loader components and lateral movement tools.
🔧 Technical Capabilities
ProjectWood propagates via spear-phishing emails containing malicious LNK files or weaponized Office documents that drop a first-stage loader. Its attack vector exploits the Follina vulnerability (CVE-2022-30190) in Microsoft Support Diagnostic Tool (MSDT) for initial compromise. The malware establishes command-and-control (C2) communication over HTTPS using custom AES-encrypted payloads, with fallback to DNS-over-HTTPS (DoH) for resilience. Persistence is achieved through scheduled tasks or registry Run keys, and it employs process hollowing to inject into legitimate processes like svchost.exe. Evasion techniques include timestamping files with legitimate Microsoft signatures, disabling Windows Defender via PowerShell commands, and using environmental keying to avoid sandbox analysis. A notable C2 domain reported by Trend Micro is update.office365-cdn[.]com (since sinkholed).
📜 History & Notable Incidents
ProjectWood was first observed in March 2022 during the Peony campaign targeting a Southeast Asian telecommunications firm. In May 2022, Trend Micro published a detailed analysis linking the malware to Earth Berberoka, noting the use of the same C2 infrastructure as the ShadowPad backdoor family. No law enforcement actions have been reported as of May 2025, but multiple C2 domains were sinkholed in collaboration with national CERTs.
🔍 Detection Indicators
Known file hashes include SHA-256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (from Trend Micro’s report). Network IOCs include connections to domains with pattern *.office365-cdn[.]com and *.cdn-azure[.]net. Registry persistence is set under HKLMSoftwareMicrosoftWindowsCurrentVersionRun with value name WindowsUpdate. Mutex name GlobalProjectWoodMutex has been observed. User-Agent string for C2 requests mimics Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36.
☠️ Risk & Impact
The malware enables full system takeover, allowing attackers to exfiltrate sensitive documents, credentials, and email archives. Impact assessments by Trend Micro indicate targeted theft of intellectual property from telecommunications and government sectors, with potential disruption of critical infrastructure. Financial losses have not been publicly quantified, but the espionage nature suggests high strategic value for victim organizations.
🛡️ Mitigation
Recommended defenses include applying patches for CVE-2022-30190 (MSDT Follina) and blocking execution of LNK files from untrusted sources. Detection rules are available in Trend Micro’s Smart Protection Network and Sigma rules for process hollowing indicators. Organizations should deploy endpoint detection and response (EDR) tools with behavioral analytics and enforce application whitelisting to prevent unknown binary execution.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.