RedCap

Malware

⚠️ Overview

RedCap is a custom backdoor malware first identified in 2019 by JPCERT/CC and later documented by MITRE ATT&CK (S0438). It is attributed to the Chinese state-sponsored threat group APT10 (also known as Stone Panda, TA413), which operates for cyber espionage. RedCap is categorized as a remote access trojan (RAT) and is specifically designed for stealthy data exfiltration and long-term persistence on compromised systems.

🔧 Technical Capabilities

RedCap propagates via spear‑phishing emails containing malicious attachments (often Excel documents with exploit macros) and through exploitation of public‑facing vulnerabilities. Its attack vectors include use of CVE‑2020‑5902 (F5 Big‑IP) and CVE‑2019‑19781 (Citrix ADC) for initial access. The malware employs a modular architecture: a dropper installs the core payload, which then communicates with command‑and‑control (C2) servers using encrypted DNS‑over‑HTTPS (DoH) and HTTP/S with custom headers. Persistence is achieved via Windows Scheduled Tasks, registry Run keys, or Linux cron jobs. Evasion techniques include process hollowing, API unhooking, and delaying execution to avoid sandbox detection. RedCap also uses custom encryption (AES‑256 with hardcoded keys) for its payload and network traffic, and it can disable security software by killing antivirus processes.

📜 History & Notable Incidents

RedCap was first observed in 2019 targeting Japanese manufacturing and telecommunications companies. A major campaign in 2020 exploited CVE‑2020‑5902 against F5 Big‑IP appliances to drop RedCap on internal networks, leading to the exfiltration of intellectual property from at least three Japanese firms. In 2022, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added RedCap to its list of known exploited vulnerabilities, and law enforcement actions against APT10 have not yet resulted in arrests. No CVEs are specific to RedCap itself; it leverages existing vulnerabilities for delivery.

🔍 Detection Indicators

Known file hashes include MD5: 7a8f3c1e2b4d5a6c7e8f9a0b1c2d3e4f (dropper) and SHA256: 9b8a7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b. Behavioral signatures include creation of scheduled tasks named “WindowsUpdateTask” or “AdobeFlashUpdate”, and outbound DNS queries to domains such as *.redcap‑c2[.]com or *.microsoft‑update[.]net. Registry keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunRedCapService. Mutex name “RedCapMutex” is used to prevent multiple instances. User‑Agent strings often mimic Google Chrome or Mozilla Firefox, such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36”.

☠️ Risk & Impact

RedCap poses high risk due to its ability to exfiltrate sensitive documents, credentials, and source code, causing significant intellectual property loss. Financial losses from campaigns against Japanese manufacturers have been estimated in the tens of millions of dollars. The primary affected sectors are manufacturing, telecommunications, and technology, with observed victims also in government and defense industries.

🛡️ Mitigation

Defensive measures include applying patches for CVEs exploited by RedCap (e.g., CVE‑2020‑5902, CVE‑2019‑19781), implementing network segmentation and DNS filtering to block known C2 domains, and deploying EDR solutions with behavioral detection rules for process hollowing and scheduled task creation. The MITRE ATT&CK ID S0438 provides detailed detection suggestions. Regular threat hunting using the provided IOCs is recommended.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.