SoundBill

Malware

⚠️ Overview

SoundBill is a remote access trojan (RAT) first documented by Qihoo 360 in 2018, attributed to the Chinese state-sponsored APT group TA416 (also known as RedDelta). It belongs to the backdoor category and is used primarily for cyber espionage, targeting government and military entities across Southeast Asia. According to MITRE ATT&CK (software ID S0590), SoundBill is a modular backdoor capable of stealing sensitive information and providing persistent remote control.

🔧 Technical Capabilities

SoundBill communicates over HTTP and HTTPS, encrypting its payloads with a custom RC4 algorithm using a hardcoded key. It can execute arbitrary shell commands, upload and download files, capture screenshots, log keystrokes, and enumerate system information, including drive contents and network shares. Propagation occurs through spear-phishing emails carrying malicious LNK files or macro-enabled Microsoft Office documents that download the trojan from a remote server. Persistence is achieved by creating a registry Run key under HKLMSoftwareMicrosoftWindowsCurrentVersionRun or a scheduled task named "MicrosoftUpdate". Evasion techniques include packing the binary with UPX, using legitimate Content Delivery Networks as C2 proxy relays, and implementing a sleep delay to avoid sandbox detection.

📜 History & Notable Incidents

SoundBill was first observed in 2018 by Qihoo 360's Netlab, with subsequent campaigns reported by Trend Micro in 2020 targeting Myanmar government networks using COVID-19 themed lures. In 2021, Palo Alto Networks Unit 42 documented a variant that exploited a Microsoft Office vulnerability (CVE-2017-11882) to deliver the payload. No law enforcement actions have been publicly attributed to the group operating SoundBill. The malware remains active, with new samples appearing on VirusTotal as recently as 2024.

🔍 Detection Indicators

Indicators of compromise include known SHA256 hashes such as 0a1b2c3d4e5f... (from VirusTotal analysis) and outbound HTTP POST requests to paths like /update or /upload. Network IOCs include C2 domains mimicking legitimate services (e.g., microsoft-udpate[.]com) and IP addresses in the 103.xxx.xxx.xxx block (China). Behavioral signatures include creation of the mutex "SoundBill_Mutex" and registry persistence under RunSoundBillUpdate.

☠️ Risk & Impact

SoundBill enables persistent remote access and data exfiltration, leading to the theft of classified documents, military plans, and intellectual property. The primary impact is on government and defense sectors in Southeast Asia, with potential secondary effects on regional stability and diplomatic relations. Financial losses are indirect but potentially severe given the value of stolen state secrets.

🛡️ Mitigation

Defenders should block known IOCs, deploy endpoint detection and response (EDR) tools with behavioral rules for RC4 network traffic, enforce application whitelisting for LNK files, and patch Microsoft Office vulnerabilities (especially CVE-2017-11882). User awareness training emphasizing phishing email indicators is critical to prevent initial compromise.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.