QUIETBOARD
Malware⚠️ Overview
QuietBoard is a modular backdoor first identified in July 2022 by the cybersecurity firm Deep Intuition (pseudonym), operated by a threat group tracked as APT-Q. It is classified as a remote access trojan (RAT) and custom botnet designed for espionage and data theft. The malware is written in C++ and uses a plugin architecture for extensibility.
🔧 Technical Capabilities
QuietBoard propagates via spear-phishing emails with malicious Office documents exploiting CVE-2021-40444 (MSHTML) to download the initial payload. It uses a multi-stage loading process with the final stage decrypted using AES-256. Its command and control (C2) infrastructure relies on HTTPS with custom XOR encryption on top of TLS to evade network detection. Persistence is achieved via a scheduled task that executes a PowerShell script to launch the malware every hour. Evasion techniques include direct system call invocation using SysWhispers2 to bypass user-mode API hooks, AMSI patching via memory modification, and disabling ETW. The malware can also perform file and registry auditing, capture screenshots, and exfiltrate data over DNS tunneling. Lateral movement is possible through SMB propagation using harvested credentials.
📜 History & Notable Incidents
The first documented campaign using QuietBoard occurred in October 2022, targeting telecommunications providers in Vietnam and Thailand, as reported by Group-IB. A second campaign in March 2023 targeted Eastern European government agencies, leveraging CVE-2021-40444 for initial access. No law enforcement actions have been publicly reported. The malware is also known to have been used against a South Korean defense contractor in a 2024 campaign, according to a report by SentinelOne.
🔍 Detection Indicators
Known file hashes include SHA256: 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 from VirusTotal. Behavioral indicators: creation of mutex "QuietBoard_Mutex_2022", outbound HTTPS to domains like update.quietboard-c2.net. Registry keys: HKCUSoftwareQuietBoardConfig. User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) QuietBoard/2.0". Network traffic may include DNS queries for subdomains of quietboard-dns.xyz for tunneling.
☠️ Risk & Impact
QuietBoard poses a high risk of long-term espionage and data exfiltration, particularly affecting telecommunications, government, and defense sectors. Financial losses are not publicly quantified but the theft of classified documents could be catastrophic. The malware's stealthy operation allows it to persist undetected for extended periods, enabling continuous compromise.
🛡️ Mitigation
Apply patches for CVE-2021-40444 and ensure email gateways block malicious Office documents with remote templates. Deploy EDR solutions with behavioral detection for AMSI patching and direct syscall. Use YARA rules to detect QuietBoard strings. Implement network segmentation and monitor for unusual DNS tunneling patterns. Block outbound connections to known quietboard domains.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.