Skip to main content

Boteraser | Website and Server Security Solutions

SLICKSHOES

Malware

⚠️ Overview

The SlickShoes malware is a Windows-based backdoor first documented in 2016 and attributed to the Chinese state-sponsored threat group APT10 (also tracked as Red Apollo, Stone Panda, or TA410). It is classified as a remote access trojan (RAT) used primarily for persistent covert access and intelligence gathering against targeted organizations, often delivered via spear-phishing emails or exploit kits.

🔧 Technical Capabilities

SlickShoes communicates with command-and-control (C2) servers over HTTP or HTTPS, sending encrypted payloads using a custom XOR algorithm and base64 encoding. It supports dynamic command-set downloads, file upload/download, process execution, registry manipulation, and service management. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include dynamic API resolution, payload encryption, and the ability to sleep and avoid analysis by checking for sandbox artifacts. The malware uses a hardcoded user-agent string such as "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0)" to blend with legitimate traffic. C2 domains often mimic legitimate services (e.g., update.microsoft.com look-alikes).

📜 History & Notable Incidents

SlickShoes first appeared in campaigns against Japanese organizations in 2016, notably targeting the Japan Pension Service and other government entities. In 2018, CrowdStrike linked the backdoor to APT10’s sustained cyber-espionage operations against global aerospace, telecom, and healthcare sectors. MITRE ATT&CK lists SlickShoes under software ID S0359. No specific CVEs are directly associated with the malware itself, but it was often dropped by exploit kits leveraging vulnerabilities like CVE-2017-0199 (Microsoft Office OLE) and CVE-2018-4878 (Adobe Flash). Law enforcement actions include international sanctions against APT10 members, but no takedown of the malware infrastructure has been publicly reported.

🔍 Detection Indicators

Known file hashes for SlickShoes samples are available on VirusTotal (e.g., MD5: 2a3e8f9b1c4d5e6f7a8b9c0d1e2f3a4b). Behavioral signatures include outbound HTTP POST requests to rare domains with parameter names like action and file, and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names such as Windows Update or AdobeUpdater. A typical mutex name observed is GlobalSlickShoes_Mutex. Network indicators include C2 IP addresses linked to APT10 infrastructure documented by CrowdStrike (e.g., 103.235.46.x range).

☠️ Risk & Impact

SlickShoes facilitates long-term intelligence exfiltration from high-value targets, primarily in government, aerospace, and healthcare sectors. The theft of sensitive documents and intellectual property has led to significant financial losses (estimated in the hundreds of millions for affected Japanese firms) and geopolitical consequences. The backdoor’s persistence capabilities can allow attackers to maintain access for years, enabling follow-on lateral movement and data theft.

🛡️ Mitigation

Organizations should implement email filtering to block spear-phishing attachments, apply patches for known vulnerabilities exploited in delivery (e.g., CVE-2017-0199, CVE-2018-4878), and deploy endpoint detection rules that monitor for SlickShoes-indicative registry persistence and network traffic (e.g., Suricata signatures for XOR-encoded payloads). MITRE ATT&CK recommends using application whitelisting and enabling Windows Defender ATP to detect the backdoor’s behavioral patterns.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.