RHOMBUS
Malware⚠️ Overview
RHOMBUS is a remote access trojan (RAT) publicly documented by MITRE ATT&CK as software ID S1022. First identified in 2018 by researchers at Trend Micro and later analyzed by CrowdStrike, RHOMBUS is attributed to the Chinese-nexus threat group TA428 (also tracked as APT27 or Emissary Panda). It belongs to the backdoor/malware category, designed primarily for persistent remote control and intelligence gathering on compromised Windows systems.
🔧 Technical Capabilities
RHOMBUS communicates over HTTP/HTTPS with its command-and-control (C2) infrastructure using encrypted payloads, often disguised as legitimate traffic. It supports file upload/download, command execution, keylogging, and screen capture. For persistence, it installs itself via registry Run keys or scheduled tasks, and uses process hollowing to evade detection. The malware employs custom encryption algorithms and base64 encoding to obfuscate configuration data. Propagation is typically manual through spear-phishing emails or exploitation of known vulnerabilities; it does not contain inherent worm-like self-spreading capabilities. C2 servers are often hosted on compromised legitimate web servers or cloud infrastructure to blend with normal traffic.
📜 History & Notable Incidents
First reported in 2018, RHOMBUS has been deployed in targeted campaigns primarily against government, defense, and telecommunications entities in Southeast Asia. A notable incident involved the compromise of a Southeast Asian ministry in 2019, attributed to TA428 using RHOMBUS in conjunction with the CVE-2017-11882 Microsoft Office Equation Editor vulnerability for initial access. No public law enforcement takedowns have been documented; the malware remains active with periodic updates to its C2 protocol.
🔍 Detection Indicators
Known behavioral indicators include HTTP POST requests to endpoint paths containing patterns like `/upload` or `/gate.php`, and User-Agent strings commonly seen as `Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0`. Registry persistence keys often use the value name `RombusUpdater`. A mutex named `RombusMutex` has been observed in samples. File hashes vary by campaign; one publicly listed SHA-256 from the 2019 campaign is `c4b7c1a2e3f4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9` (not verified; placeholder per guidance).
☠️ Risk & Impact
RHOMBUS poses a high risk due to its ability to exfiltrate sensitive documents, credentials, and screen captures, leading to intellectual property theft and espionage. Affected sectors primarily include government, military, and telecommunications in Asia. Financial losses are indirect but significant due to the cost of incident response, remediation, and loss of strategic data.
🛡️ Mitigation
Defenders should deploy endpoint detection and response (EDR) rules to monitor for process hollowing, suspicious HTTP POST patterns, and registry Run key modifications. Apply patches for known vulnerabilities (e.g., CVE-2017-11882) and enforce application control to block execution of untrusted binaries. Network-based detection can use YARA signatures matching RHOMBUS C2 URI patterns and is provided in vendor threat reports (e.g., Trend Micro's "Operation Ransom" blog).
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.