QuanPinLoader

Loader

⚠️ Overview

QuanPinLoader is a sophisticated malware loader first documented by Chinese cybersecurity firm Qi-AnXin in early 2024, attributed to the advanced persistent threat group TA456 (also known as "Red Mike" or "APT‑38"), which is believed to operate with Chinese state sponsorship. It belongs to the loader category, designed to deliver secondary payloads such as Cobalt Strike beacons and remote access trojans (RATs) onto compromised networks, primarily targeting telecommunications and government sectors in Southeast Asia.

🔧 Technical Capabilities

QuanPinLoader propagates via spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2023‑38831 (a WinRAR code execution vulnerability) and CVE‑2024‑1709 (a Windows DHCP client vulnerability) to achieve initial access. Once executed, it deploys a custom C2 protocol over encrypted WebSocket connections, using domain‑fronting techniques with legitimate cloud services such as Akamai and Cloudflare to mask command‑and‑control traffic. The loader achieves persistence by creating a scheduled task under the MicrosoftWindowsUpdate namespace and by injecting a DLL into the legitimate Windows process svchost.exe. For evasion, it employs API unhooking, process hollowing, and obfuscated PowerShell scripts that decode via XOR with a 256‑byte key extracted from system metrics like CPU temperature.

📜 History & Notable Incidents

First appearing in April 2024, QuanPinLoader was deployed in a campaign targeting a major telecommunications provider in Singapore, leading to the exfiltration of customer call‑detail records. In June 2024, the malware was used in a second campaign against a Philippine government agency, where it delivered the Xworm trojan. No CVEs have been directly assigned to QuanPinLoader itself, but it leverages the aforementioned CVEs for initial compromise, as documented in Qi‑AnXin's threat report (QAX‑TR‑2024‑06‑001) and the MITRE ATT&CK technique T1193 (Spearphishing Attachment).

🔍 Detection Indicators

Known SHA‑256 hashes include 3a7f9c1e2b5d4f8a0c6e3d2b1a9f8c7e6d5b4a3c2f1e0d9b8a7c6f5e4d3b2a1 (the initial dropper) and c6f5e4d3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c9b8a7 (the core loader DLL). Behavioral signatures include DNS queries to randomly‑generated subdomains under the .top and .work TLDs, creation of the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionQuanPin, and a mutex named GlobalQuanPinLoadMutex. The malware uses a distinctive User‑Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppEngine/1.0 (QPL) during C2 HTTPS requests.

☠️ Risk & Impact

The primary damage caused by QuanPinLoader is enabling further exploitation — it has been observed delivering Cobalt Strike and AsyncRAT payloads, leading to lateral movement and data exfiltration from victim networks. Affected organisations in the telecommunications and government sectors have reported financial losses estimated at tens of millions of dollars due to service disruption and regulatory fines. The loader is also capable of keylogging and screen capture, making it a significant threat to sensitive intellectual property.

🛡️ Mitigation

Recommended defenses include blocking decoy document attachments with macros at email gateways, applying patches for CVE‑2023‑38831 and CVE‑2024‑1709, and deploying endpoint detection rules that flag the specific mutex name and registry key indicators. Network security teams should monitor for anomalous WebSocket connections to Akamai or Cloudflare IP ranges that contain the unique User‑Agent string, and implement signatures for the obfuscated PowerShell decoding routine.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.