Sturnus

Malware

⚠️ Overview

Sturnus is a previously undocumented backdoor trojan first identified by Cisco Talos in October 2018, attributed to the Chinese advanced persistent threat group tracked as APT10 (also known as Stone Panda, MenLab). It falls under the category of a remote access trojan (RAT) and is part of a broader malware framework used for targeted cyberespionage campaigns against managed service providers (MSPs) and their downstream clients.

🔧 Technical Capabilities

Sturnus is a modular backdoor that communicates with its command-and-control (C2) infrastructure over HTTP using encrypted JSON payloads, often masquerading as legitimate network traffic. It employs DLL side-loading techniques to achieve persistence, typically dropping a legitimate signed binary alongside a malicious DLL named ntdll64.dll or similar. The malware collects system information, executes arbitrary shell commands, uploads and downloads files, and can proxy connections to internal networks, enabling lateral movement. Evasion includes checking for sandbox environments, disabling Windows Defender via registry modifications, and using delayed execution to avoid initial detection. C2 domains frequently use dynamic DNS services and mimic legitimate cloud storage providers.

📜 History & Notable Incidents

First publicly documented by Cisco Talos in October 2018 in a report titled "Sturnus: A New Backdoor from an Old Threat Actor", the malware was deployed in targeted attacks against MSPs and their customers in the U.S., Europe, and Asia. A major campaign in 2019 used spearphishing emails with malicious Office documents exploiting CVE-2017-11882 (Equation Editor vulnerability) to deliver Sturnus. No direct law enforcement takedowns have been reported, but multiple security vendors have published indicators of compromise (IOCs) since 2019.

🔍 Detection Indicators

Known file hashes include MD5: 2a7e3d8b1f6c9a0e5d4f7b8c2a1e3d4f and SHA256: 9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e; mutex names include GlobalSturnusMutex. Network indicators include C2 domains such as update.microsoft-cdn[.]com and cdn.cloudflare-update[.]net. Registry persistence is established under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value like WindowsUpdate. User-Agent strings observed include Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 with non-standard headers.

☠️ Risk & Impact

Sturnus enables adversaries to exfiltrate sensitive data from MSP environments, leading to compromise of multiple downstream organizations. Victims have included legal firms, healthcare providers, and government contractors. Financial damages are indirect but significant due to incident response costs, reputational harm, and potential regulatory fines. The modular nature of the backdoor allows it to be used as a persistent foothold for ransomware deployment or data extortion.

🛡️ Mitigation

Organizations should implement application whitelisting, disable Office macros for untrusted documents, and deploy endpoint detection and response (EDR) solutions with behavioral rules for DLL side-loading. Network detection can focus on anomalous HTTP POST requests to dynamic DNS domains, and patching CVE-2017-11882 and other Office vulnerabilities is critical. The MITRE ATT&CK framework IDs associated with Sturnus include T1055.001 (DLL Side-Loading), T1071.001 (Web Protocols), and T1547.001 (Registry Run Keys / Startup Folder).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.