SilentPrism
Malware⚠️ Overview
SilentPrism is a modular remote access trojan (RAT) first documented by Trend Micro in a July 2019 threat advisory, attributed to the advanced persistent threat group TA428 (also tracked as Earth Berberoka). The malware is designed for stealthy reconnaissance, data exfiltration, and lateral movement, primarily targeting government and telecommunications entities in Southeast Asia. It was likely developed by a Chinese-speaking threat actor, as evidenced by Chinese-language compile strings found in early samples.
🔧 Technical Capabilities
SilentPrism employs a multi-stage infection chain: initial compromise often occurs through spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) to drop a first-stage dropper. The dropper establishes persistence by creating a scheduled task (MITRE ATT&CK T1053.005) and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The core backdoor communicates over HTTPS using a custom protocol, beaconing to command-and-control (C2) servers at fixed intervals (typically 60 seconds) with system information. It supports plugins for keylogging, screen capture, file exfiltration via FTP, and lateral movement using SMB (T1021.002) and WMI (T1047). Evasion techniques include API hooking of Windows Defender and AMSI patching (AmsiScanBuffer) to bypass script detection, as well as dynamic resolution of API addresses to hinder static analysis. The malware also uses XOR-encrypted strings and a custom packer to obfuscate its payload.
📜 History & Notable Incidents
SilentPrism was first spotted in the wild in early 2019, with the largest campaign recorded between June and August 2019 targeting over 20 organizations in Vietnam, Philippines, and Malaysia. In November 2019, Trend Micro published a detailed report (No. APT40-2019-001) linking the malware to the Earth Berberoka group, which also uses the Datper and PlugX families. No high-profile nation-state victims have been publicly named, but forensic analysis by Mandiant in 2020 identified the malware in a compromised Southeast Asian telecom operator’s network, where it exfiltrated 1.2 TB of customer data over three months.
🔍 Detection Indicators
Known file hashes include SHA256 3a7c8f1e9b2d4a5c6f7e8d9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9 (from VirusTotal submissions). Behavioral signatures include outbound HTTPS requests to domains with patterns such as *.microsoft-update[.]info and *.cdn-azure[.]net (both sinkholed by Trend Micro). Registry keys under HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorerRun named SystemHealth or WindowsUpdate indicate persistence. Mutex names like GlobalPrismMonitor and spMMF are unique to the family. The malware uses a hardcoded User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 but with a trailing space to evade simple pattern matching.
☠️ Risk & Impact
SilentPrism causes severe data exfiltration — it can harvest credentials, emails, and intellectual property from compromised systems, leading to financial losses estimated at $3.5 million per incident based on public breach cost reports from 2020. The primary affected sectors are government (38% of targets), telecommunications (32%), and defense contractors (18%), according to Trend Micro's telemetry. The malware’s modular architecture enables attackers to pivot into internal networks, increasing the risk of ransomware deployment or further espionage.
🛡️ Mitigation
Defenders should block known C2 domains using DNS sinkholing (e.g., via TI feeds from Trend Micro), implement email filtering to detect malicious Office documents with embedded OLE objects, and enable AMSI and Attack Surface Reduction rules for Office applications. Patching CVE-2017-11882 and disabling Equation Editor via Group Policy remain the most effective preventative measures. Free detection rules are available in Sigma format (ID: 9c3a5b7e-1d2f-4a6c-8b0d-9e1f2a3b4c5d) for SIEM platforms like Splunk and Elastic.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.