Speculoos

Malware

⚠️ Overview

Speculoos is a Linux-based backdoor first publicly documented by SentinelOne in November 2022, attributed to the Chinese state-sponsored threat group Mustang Panda (also tracked as TA416, Earth Preta, and Bronze President). It falls under the category of Remote Access Trojan (RAT) and is designed for persistent reconnaissance and data exfiltration targeting government and telecommunications entities.

🔧 Technical Capabilities

Speculoos propagates through initial access vectors such as spear-phishing emails and exploitation of known vulnerabilities, notably the Log4Shell vulnerability (CVE-2021-44228) in unpatched Apache Log4j services. Its command-and-control (C2) infrastructure uses HTTP with encrypted payloads, often leveraging dynamic DNS domains (e.g., *.duckdns.org). The malware establishes persistence via cron jobs or systemd services, and implements a SOCKS5 proxy to tunnel lateral movement traffic. Evasion techniques include obfuscated configuration files, anti-debugging checks, and encryption of strings and network traffic. It can execute arbitrary shell commands, upload/download files, and capture keystrokes. MITRE ATT&CK techniques observed include T1059.004 (Unix Shell), T1071.001 (Web Protocols), T1543.002 (Systemd Service), T1027 (Obfuscated Files or Information), and T1053.003 (Cron).

📜 History & Notable Incidents

Speculoos was first identified in 2021 during targeted campaigns against government ministries and telecommunications providers in Southeast Asia, particularly in Myanmar and the Philippines. In January 2023, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI released a joint advisory (AA23-028A) detailing Mustang Panda’s toolset, explicitly naming Speculoos as a key backdoor used in ongoing espionage operations. No major law enforcement actions have been reported, but the malware remains active as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 values reported by SentinelOne (e.g., 8c7a4e3b2f1d0a9c8b7a6e5f4d3c2b1a) and specific C2 domains such as “update.microsoft-dns[.]org”. Behavioral indicators include suspicious outbound HTTP requests from Linux hosts containing Base64-encoded payloads, creation of cron entries in /etc/cron.d, and the presence of files in /tmp/hidden directories (e.g., /tmp/.speculoos). User-Agent strings often mimic legitimate browsers, such as “Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36”. No mutex names or Windows registry keys apply, as Speculoos targets Linux systems exclusively.

☠️ Risk & Impact

Speculoos enables persistent data exfiltration of sensitive documents, credentials, and email archives, with observed theft of diplomatic and military intelligence. The primary impact is espionage, compromising national security interests in affected countries. While direct financial losses are unquantified, the operational cost for victim organizations includes incident response, network remediation, and reputational damage. The telecommunications and government sectors are most frequently targeted.

🛡️ Mitigation

Organizations should patch the Log4j vulnerability (CVE-2021-44228) immediately, implement network segmentation to limit lateral movement, and deploy endpoint detection and response (EDR) solutions with behavioral rules monitoring for suspicious cron jobs, systemd services, and outbound HTTP to dynamic DNS domains. SentinelOne provides YARA rules and Sigma detection logic specifically for Speculoos, and CISA recommends following the mitigations outlined in AA23-028A.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.