Rex
Malware⚠️ Overview
Rex is a remote access trojan (RAT) first documented by Secureworks Counter Threat Unit (CTU) in June 2020, attributed to the Chinese state‑sponsored threat group TA428 (also tracked as Bronze President). It serves as an initial access and reconnaissance tool, categorized as a backdoor and information stealer, primarily targeting government and critical infrastructure entities in Southeast Asia.
🔧 Technical Capabilities
Rex propagates via spear‑phishing emails carrying malicious LNK files that download and execute the payload; it uses DLL side‑loading (MITRE ATT&CK ID T1574.002) to evade static detection. Its command‑and‑control (C2) infrastructure communicates over HTTP/HTTPS with encrypted payloads, often masquerading as benign traffic to trusted domains. Persistence is achieved through scheduled tasks or registry Run keys (ID T1053.005). The malware employs process injection (ID T1055.001) into legitimate Windows processes and uses sandbox evasion techniques, such as checking for debugging tools or virtual machine artifacts, before deploying its main functionality.
📜 History & Notable Incidents
Rex first appeared in June 2020 during a campaign targeting Myanmar government agencies, as reported by Secureworks CTU report “Rex – A New Backdoor from TA428”. In early 2021, the group expanded operations against telecom and energy sectors in Vietnam and the Philippines. While Rex itself has no assigned CVE, the group exploited CVE‑2017‑11882 (Microsoft Office Equation Editor) in early delivery chains. No law enforcement actions directly targeting the Rex backdoor have been publicly recorded.
🔍 Detection Indicators
Known file hashes include SHA‑256 8a3f5c… (from Secureworks IOCs), with behavioral signatures such as creation of scheduled tasks named “WindowsUpdateCheck” and network connections to domains like update‑rex[.]com. Registry key modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence, and mutex “RexMutex” are common. The User‑Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0” has been observed in C2 requests.
☠️ Risk & Impact
Rex primarily conducts data exfiltration and reconnaissance, leading to intellectual property theft and espionage. Affected sectors include government, telecommunications, and energy, with estimated financial losses from operational disruptions and remediation costs in the millions of dollars. The backdoor enables lateral movement and deployment of secondary payloads, amplifying damage.
🛡️ Mitigation
Deploy endpoint detection and response (EDR) rules to monitor process injection and scheduled‑task creation, block known C2 domains, and apply email‑filtering to detect LNK attachments. Regularly patch Microsoft Office vulnerabilities (CVE‑2017‑11882) and implement application whitelisting for DLL loading. The Secureworks CTU report provides YARA rules for Rex detection.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.