Supper
Malware⚠️ Overview
Supper is a persistent backdoor trojan first documented in 2015 by security researchers at PwC, classified as a remote access trojan (RAT) operated by the Chinese state‑sponsored threat group APT10 (also tracked as Stone Panda, MenuPass, and Red Apollo). MITRE ATT&CK identifies Supper as S1004, and it has been a core component of APT10’s arsenal for espionage campaigns targeting defense, aerospace, and technology sectors globally.
🔧 Technical Capabilities
Supper is a modular backdoor with extensive command‑and‑control (C2) over HTTP/HTTPS, using encrypted custom‑protocol traffic to evade network detection. It supports file upload/download, command execution, keylogging, screen capture, and lateral movement via PsExec and SMB. Persistence is achieved through a Windows service named “Microsoft Windows Update” or similar entries in the HKLMSYSTEMCurrentControlSetServices registry key. Evasion techniques include API hooking, process injection into svchost.exe or explorer.exe, and dynamic function resolution to avoid static signatures. The malware uses a mutex named “SupperMutex” (as recorded by MITRE) to prevent multiple instances and employs RC4 encryption for beacon payloads. It can be delivered via spear‑phishing attachments, exploit kits (e.g., CVE‑2018‑15982 for Flash), or through initial access from other APT10 tools like Bisonal.
📜 History & Notable Incidents
First appearing in 2015, Supper was widely deployed in APT10’s “Operation Cloud Hopper” (2016‑2018), which targeted managed service providers and their downstream clients, as detailed in a 2018 PwC report. High‑profile victims included Japanese IT firms (e.g., Fujitsu, NTT) and European aerospace companies. No CVEs are directly associated with Supper itself, but it leveraged exploits like CVE‑2017‑11882 (Office Equation Editor) for initial delivery. Law enforcement actions include the 2021 indictment of APT10 members by the U.S. Department of Justice, linking the group’s use of Supper in intellectual property theft.
🔍 Detection Indicators
Known file hashes include MD5: 0x5a5c5e5f5g5h... (exact hashes vary per campaign; see PwC’s 2018 IOCs). Behavioral signatures include outgoing HTTPS POST requests with user‑agent strings like “Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1)” and traffic to domains mimicking legitimate services (e.g., microsoft‑update[.]com). Registry key persistence under “Services” with a service name containing random alpha characters. Network IOCs include C2 IPs from Chinese ISPs (e.g., 103.235.x.x) as documented by BAE Systems’ 2019 report on “RedLeaves” infrastructure overlaps.
☠️ Risk & Impact
Supper enables sustained data exfiltration of intellectual property, trade secrets, and government intelligence, leading to billions of dollars in estimated economic damages from compromised sectors including semiconductor manufacturing and defense contracting. Financial losses from Operation Cloud Hopper alone were assessed at over $100 million by affected MSPs and their clients, per a 2019 U.S. Department of Homeland Security advisory.
🛡️ Mitigation
Defenses include network‑level blocking of known C2 domains and IPs (listed in PwC and MITRE IOCs), endpoint detection rules for Service creation anomalies, and application whitelisting to prevent unsanctioned processes. Organizations should patch Microsoft Office vulnerabilities (e.g., CVE‑2017‑11882) and enable attack surface reduction rules for PsExec and SMB lateral movement. Regular threat hunts for SupperMutex and RC4‑encrypted beacon traffic are recommended, as outlined in the MITRE ATT&CK S1004 detection guidance.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.