S-Type is a backdoor trojan first documented in early 2024 by the QiAnXin Threat Intelligence Center, attributed to the advanced persistent threat group APT-Q-27 (also tracked as Earth Preta or Mustang Panda). It belongs to the category of remote access trojans (RATs) and is primarily used for espionage operations targeting government and diplomatic entities in Southeast Asia.
S-Type employs spear-phishing emails with malicious LNK or ISO attachments as its primary initial access vector. The malware establishes encrypted C2 communication over HTTPS using a custom TLS implementation, with beacon intervals ranging from 30 seconds to 5 minutes. Persistence is achieved via Windows scheduled tasks or registry Run keys, often masquerading as legitimate system processes (e.g., svchost.exe). Evasion techniques include API unhooking, process hollowing into explorer.exe, and dynamic resolution of API calls to bypass static detection. It utilizes a modular plugin architecture to load additional components for keylogging, screenshot capture, and file exfiltration. The backdoor supports file upload/download, command execution, and proxy tunneling through the C2 server.
S-Type was first observed in January 2024 targeting the Ministry of Foreign Affairs of Myanmar. A major campaign in March 2024 compromised a Southeast Asian defense ministry, exfiltrating classified diplomatic cables. No CVEs are directly associated with S-Type; it relies on social engineering and user execution of malicious attachments. Law enforcement agencies, including Singapore's CSA, have issued advisories detailing the malware's infrastructure but no arrests have been reported.
Known file hashes include SHA256: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (sample from QiAnXin report). Behavioral signatures include creation of scheduled tasks named "SystemUpdateTask" and outbound connections to IP ranges 103.xx.xx.xx (resolved to VPS providers in Hong Kong). Registry keys modified under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values like "svchost_update". Mutex name "S-Type_Mutex_2024" has been observed. User-Agent strings mimic Google Chrome 120 on Windows 10.
S-Type enables complete remote control over infected hosts, leading to data exfiltration of diplomatic communications, military plans, and sensitive government personnel records. Financial losses are indirect but significant due to compromised national security posture. The primarily affected sectors are government, defense, and foreign ministries across Southeast Asia and the South China Sea region.
Recommended defenses include blocking execution of LNK and ISO files from email attachments, implementing application allowlisting for uncommon processes, and deploying EDR solutions with behavioral detection rules for process hollowing and scheduled task abuse. Organizational network segmentation and monitoring outbound HTTPS connections to known malicious IP ranges are advised.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.