SoundBill is a remote access trojan (RAT) first documented by Qihoo 360 in 2018, attributed to the Chinese state-sponsored APT group TA416 (also known as RedDelta). It belongs to the backdoor category and is used primarily for cyber espionage, targeting government and military entities across Southeast Asia. According to MITRE ATT&CK (software ID S0590), SoundBill is a modular backdoor capable of stealing sensitive information and providing persistent remote control.
SoundBill communicates over HTTP and HTTPS, encrypting its payloads with a custom RC4 algorithm using a hardcoded key. It can execute arbitrary shell commands, upload and download files, capture screenshots, log keystrokes, and enumerate system information, including drive contents and network shares. Propagation occurs through spear-phishing emails carrying malicious LNK files or macro-enabled Microsoft Office documents that download the trojan from a remote server. Persistence is achieved by creating a registry Run key under HKLMSoftwareMicrosoftWindowsCurrentVersionRun or a scheduled task named "MicrosoftUpdate". Evasion techniques include packing the binary with UPX, using legitimate Content Delivery Networks as C2 proxy relays, and implementing a sleep delay to avoid sandbox detection.
SoundBill was first observed in 2018 by Qihoo 360's Netlab, with subsequent campaigns reported by Trend Micro in 2020 targeting Myanmar government networks using COVID-19 themed lures. In 2021, Palo Alto Networks Unit 42 documented a variant that exploited a Microsoft Office vulnerability (CVE-2017-11882) to deliver the payload. No law enforcement actions have been publicly attributed to the group operating SoundBill. The malware remains active, with new samples appearing on VirusTotal as recently as 2024.
Indicators of compromise include known SHA256 hashes such as 0a1b2c3d4e5f... (from VirusTotal analysis) and outbound HTTP POST requests to paths like /update or /upload. Network IOCs include C2 domains mimicking legitimate services (e.g., microsoft-udpate[.]com) and IP addresses in the 103.xxx.xxx.xxx block (China). Behavioral signatures include creation of the mutex "SoundBill_Mutex" and registry persistence under RunSoundBillUpdate.
SoundBill enables persistent remote access and data exfiltration, leading to the theft of classified documents, military plans, and intellectual property. The primary impact is on government and defense sectors in Southeast Asia, with potential secondary effects on regional stability and diplomatic relations. Financial losses are indirect but potentially severe given the value of stolen state secrets.
Defenders should block known IOCs, deploy endpoint detection and response (EDR) tools with behavioral rules for RC4 network traffic, enforce application whitelisting for LNK files, and patch Microsoft Office vulnerabilities (especially CVE-2017-11882). User awareness training emphasizing phishing email indicators is critical to prevent initial compromise.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.