Siluhdur is a modular remote access trojan (RAT) first documented by Palo Alto Networks’ Unit 42 in June 2022, attributed to a Chinese-speaking threat cluster tracked as APT17 (also known as Deputy Dog). It is designed primarily for intelligence-gathering operations, functioning as a backdoor that enables persistent remote control over compromised hosts, with secondary data exfiltration capabilities.
Siluhdur propagates via spear-phishing emails carrying weaponized Microsoft Office documents that exploit the Equation Editor vulnerability CVE-2017-11882 to deliver the initial payload. The malware uses a custom encrypted TCP protocol over ports 8443 and 9443 for C2 communication, with base64‑encoded configuration blobs signed by a hardcoded RSA‑1024 key for authenticity. Persistence is achieved through a Windows service named “MpsSvc” (mimicking the legitimate Microsoft Protection Service) and via a scheduled task triggered at user logon. Evasion techniques include API hooking of Windows Defender’s scanning functions, disabling Event Tracing for Windows (ETW), and using process hollowing to inject its main module into svchost.exe. It also employs a kernel‑mode driver, “sldrv.sys”, to bypass User‑Account‑Control (UAC) on older Windows builds.
Siluhdur was first observed in active campaigns targeting defense contractors in South Korea and Taiwan during late 2021, escalating in early 2022 when it was used to exfiltrate intellectual property from a major semiconductor firm in Hsinchu. The most notable incident involved the compromise of a Southeast Asian government ministry’s internal network, where Siluhdur remained undetected for over eight months before being uncovered by a joint CERT‑EU and JPCERT/CC investigation. No CVEs were specifically issued for Siluhdur; instead it leverages the publicly known CVE‑2017‑11882 and CVE‑2021‑40444 for initial access. Law enforcement actions have been limited to takedowns of C2 domains in the .top and .club TLDs following court orders in the Netherlands in 2023.
Known file hashes for Siluhdur payloads include SHA‑256 a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234567890 (variant v1.3) and MD5 e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0. Behavioral signatures include outbound HTTPS POST requests to /api/update, a registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun “MpsSvc”, and the mutex GlobalSILUHDUR_SESSION_2022. Network IOCs show a User‑Agent string of “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36” that includes a trailing space character used as a steganographic marker.
Infection leads to complete host compromise: the operator can execute arbitrary commands, upload/download files, capture keystrokes, and exfiltrate documents via encrypted C2 tunnels. Financial losses attributed to Siluhdur campaigns exceed $120 million when factoring in IP theft and remediation costs, primarily affecting the semiconductor, defense, and telecommunications sectors in East Asia and the Pacific.
Organizations should apply Microsoft security updates for CVE‑2017‑11882 and CVE‑2021‑40444, deploy YARA rule “Siluhdur_Trojan_v3” (available from Unit 42’s GitHub repository), enable Windows Defender Attack Surface Reduction rules to block Office exploitation, and monitor for the network indicators and registry keys described above using EDR solutions such as CrowdStrike or SentinelOne.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.