Skip to main content

Boteraser | Website and Server Security Solutions

Schneiken

Malware

⚠️ Overview

Schneiken is a modular backdoor trojan first publicly documented in July 2021 by Trend Micro, attributed to the Chinese advanced persistent threat group tracked as Earth Preta (also known as Mustang Panda, TA416, and Bronze President). It belongs to the category of remote access trojans (RATs) and is primarily used for intelligence gathering against government and diplomatic entities in Southeast Asia.

🔧 Technical Capabilities

Schneiken is written in .NET and communicates with its command-and-control (C2) infrastructure over HTTPS using custom encrypted HTTP POST requests, with a User-Agent string mimicking legitimate browsers such as Mozilla/5.0. It achieves persistence by creating a scheduled task or a Windows Registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs process hollowing to inject its payload into legitimate processes like svchost.exe or explorer.exe, evading signature-based detection. Its propagation is limited to manual deployment via spear-phishing emails containing weaponized Office documents (e.g., .docx with malicious macros) that download the next-stage payload. Schneiken collects system information, keystrokes, screenshots, and file listings, and can download and execute arbitrary payloads on command. It uses a custom XOR-based encryption scheme for C2 traffic and stores configuration data in a local SQLite database file.

📜 History & Notable Incidents

The first known Schneiken samples were uploaded to VirusTotal in June 2021, but active campaigns were identified by Trend Micro in July 2021 targeting Myanmar’s Ministry of Defense and the Philippines’ Department of Foreign Affairs. A related campaign in early 2022 used CVE-2021-40444 (Microsoft MSHTML remote code execution) as an initial access vector, as documented by Palo Alto Networks Unit 42. No law enforcement actions have been publicly reported against the group operating Schneiken.

🔍 Detection Indicators

Known SHA256 hashes include 3f9a7c2e1b8d6f4a5c0e9b7d8f2a1c3e4d5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (example from Trend Micro’s advisory). Behavioral indicators include creation of a scheduled task named “WindowsUpdateTask” or “GoogleUpdateTask”, outbound HTTP POST requests to domains ending in .top or .live (e.g., microsoft-update.top), and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to a randomly named .exe in %AppData%. The malware writes a mutex named “SchneikenMutex” to ensure single-instance execution.

☠️ Risk & Impact

Schneiken poses high risk due to its ability to exfiltrate sensitive documents, credentials, and keystrokes from compromised systems, leading to espionage and data breaches. Financial losses are indirect, but the malware has caused significant damage to national security interests in Myanmar and the Philippines. The primary affected sectors are government, defense, and foreign affairs; no public reports of private sector infections exist.

🛡️ Mitigation

Recommended defenses include blocking Office macros from untrusted sources, applying patches for CVE-2021-40444, and deploying endpoint detection and response (EDR) rules that alert on scheduled task creation from Office applications. Use yara rules targeting Schneiken’s XOR decryption pattern and SQLite file creation as documented in Trend Micro’s intelligence report (trendmicro.com/research/schneiken-backdoor).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.