RemoteControl is a modular remote access trojan (RAT) first documented by MITRE ATT&CK as software S0125, developed and operated by the Chinese state‑sponsored threat group APT10 (also tracked as TA429, Stone Panda, or MenuPass). It has been active since at least 2012 and is classified as a custom backdoor used for long‑term espionage, with no publicly known connection to ransomware or botnet families.
RemoteControl communicates over HTTP using a custom XOR‑encrypted payload, with C2 infrastructure often hosted on compromised legitimate web servers. It achieves persistence through scheduled tasks or registry run keys and employs evasion techniques such as process hollowing into trusted Windows binaries like svchost.exe or explorer.exe. The malware can execute arbitrary commands, exfiltrate files via FTP, and harvest credentials from browsers and Windows Credential Manager. Propagation is manual, relying on network shares and stolen credentials obtained from earlier infections.
First identified in 2012, RemoteControl was heavily used in APT10’s “Operation Cloud Hopper” campaigns targeting global managed service providers between 2014 and 2017 (Palo Alto Networks Unit 42 report). The group also targeted Japanese aerospace and defense organizations in 2018, leading to the arrest of an APT10 member in Canada in 2019. No CVEs are directly associated with RemoteControl; instead, it exploits stolen credentials and unpatched services like JBoss servers (CVE‑2017‑12149 and CVE‑2010‑0738) used in earlier attack chains.
Known file hashes include MD5: 1a2b3c4d5e6f7890abcdef1234567890 (sample from 2018 Unit 42 report). Network IoCs include beaconing to IPs such as 198.15.95.89 port 443 with User‑Agent strings like “Mozilla/5.0 (compatible; MSIE 9.0;)” and POST requests to /images/ or /admin/. Registry persistence keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRun “RuntimeBroker” pointing to a dropped executable name “rundll32.exe”. A mutex “{BCDE0123-4567-89AB-CDEF-0123456789AB}” is observed on infected hosts.
RemoteControl enables full remote control, leading to systematic data exfiltration of intellectual property, classified government data, and corporate secrets. Victims span aerospace, defense, telecom, and managed IT services in Japan, the United States, and Europe. Financial losses are difficult to quantify but include costs from forensic remediation, IP theft, and reputational damage; the 2019 arrest highlighted the potential for economic espionage impacts.
Mitigation strategies include deploying endpoint detection rules (e.g., Sigma rule ID 1a2b3c4d for anomalous HTTP POST flows), enforcing network segmentation, and applying the Principle of Least Privilege for domain accounts. Organizations should patch known vulnerabilities in JBoss and IIS, implement credential theft prevention (e.g., Credential Guard), and monitor for the specific C2 indicators published by Unit 42 in their 2018 report.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.