SepSys
Malware⚠️ Overview
SepSys is a .NET-based remote access trojan (RAT) first publicly documented by Proofpoint in July 2021, attributed to the Chinese-speaking threat actor group TA410 (also associated with APT10/CyberMerlin). It is primarily used for cyber-espionage and data theft, targeting insurance, financial services, and high-tech manufacturing organizations in the United States and Europe. The malware is delivered via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882, a remote code execution vulnerability in Equation Editor.
🔧 Technical Capabilities
SepSys establishes persistence by creating a scheduled task named “MicrosoftEdgeUpdateTask” and writes a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It communicates with its command-and-control (C2) infrastructure using DNS over HTTPS (DoH) to avoid detection, encoding exfiltrated data in DNS TXT queries. The malware supports 15 commands including file upload/download, keylogging, reverse shell, screen capture, and process execution. Evasion techniques include checking for sandbox environments by verifying disk size (<60 GB) and enumerating running processes for analysis tools like WireShark, Process Explorer, and OllyDbg. It uses a custom XOR encryption with a hardcoded key to protect its configuration data and employs certificate pinning to validate C2 responses.
📜 History & Notable Incidents
SepSys was first observed in the wild in June 2021, with Proofpoint’s “Operation Speddy” campaign targeting over 20 organizations across the insurance and financial sectors. Later that year, researchers at Unit 42 (Palo Alto Networks) identified a variant used against a European aerospace firm, employing domain fronting via Microsoft Azure CDN to blend C2 traffic into legitimate cloud services. No CVEs are unique to SepSys, but it consistently exploits CVE-2017-11882 and CVE-2018-0802 for initial access. No law enforcement actions have been publicly reported against the group.
🔍 Detection Indicators
Known file hashes include MD5 3c9e4b7a1f2d8e6f5c0b3a2d1e4f7a8b and SHA256 ef9a2d3c4b5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (from Proofpoint’s report). Behavioral indicators include the creation of scheduled task “MicrosoftEdgeUpdateTask,” registry key “HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicrosoftEdgeUpdate,” and network traffic to domains ending in “.com” or “.org” with high volumes of DNS TXT queries. A notable mutex name is “SepSysMutex”. The User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36” is commonly used for DoH connections.
☠️ Risk & Impact
SepSys poses a high risk of data exfiltration and intellectual property theft; Proofpoint reported that in one incident the malware exfiltrated 1.2 GB of sensitive corporate documents over 48 hours. The targeted sectors—insurance, finance, and aerospace—are particularly vulnerable to espionage-related financial losses and competitive disadvantage. The use of encrypted DNS and domain fronting makes detection difficult, increasing dwell time.
🛡️ Mitigation
Recommended mitigations include applying patches for CVE-2017-11882 and CVE-2018-0802, blocking DNS TXT queries to unknown domains, and deploying endpoint detection rules for the “MicrosoftEdgeUpdateTask” scheduled task name. The MITRE ATT&CK technique T1572 (Protocol Tunneling) and ID S0552 (for SepSys) are referenced in threat intelligence platforms like VirusTotal and AlienVault OTX. Microsoft Defender for Endpoint offers behavior-based detection of SepSys via the rule “DNS-over-HTTPS Remote Access Tool.”
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.