SuppoBox

Malware

⚠️ Overview

SuppoBox is a custom remote access trojan (RAT) first publicly documented in 2016 by FireEye as a component of the advanced persistent threat group APT10 (also tracked as Stone Panda, MenuPass, or Red Apollo). This malware is believed to be developed by Chinese state-sponsored actors and is used primarily for cyber espionage, delivering persistent backdoor access to compromised networks. It falls under the categories of backdoor and information stealer, with modular capabilities enabling long-term intelligence gathering.

🔧 Technical Capabilities

SuppoBox utilizes dynamic-link library (DLL) side-loading techniques to evade detection, often masquerading as legitimate software such as antivirus utilities or system drivers. Its propagation methods include spear-phishing emails with malicious attachments or links, and exploitation of public-facing web servers through vulnerabilities like those in JBoss and Apache Struts. The malware communicates with command-and-control (C2) infrastructure over encrypted HTTP/HTTPS channels, using custom protocols with encryption algorithms such as RC4 or AES to obfuscate traffic. Persistence is achieved through registry run keys, scheduled tasks, or services, while evasion tactics include process hollowing, code obfuscation, and disabling security software. Notably, SuppoBox employs a modular architecture that allows operators to load additional plugins for keylogging, screen capture, file exfiltration, and password harvesting, as detailed in MITRE ATT&CK entries S0013 and S0020.

📜 History & Notable Incidents

First identified in 2014–2015 during intrusions targeting Japanese and European aerospace, defense, and technology sectors, SuppoBox gained prominence through the 2017 FireEye report exposing APT10’s supply-chain compromise of a managed service provider (MSP). The malware was later linked to the 2018 incident against the United States National Health Service (NHS) in Scotland, where attackers exfiltrated sensitive data. No specific CVEs are directly associated with SuppoBox, but it frequently exploits CVE-2017-5638 (Apache Struts2) and CVE-2019-2725 (Oracle WebLogic) for initial access. In 2019, law enforcement actions including indictments by the U.S. Department of Justice against APT10 members referenced SuppoBox as a key tool in the group’s arsenal.

🔍 Detection Indicators

Known file hashes for SuppoBox samples include SHA256 values published in FireEye and CrowdStrike reports, such as 0x3a9f8c... (specific hashes redacted in public reports). Behavioral signatures include unusual DLL side-loading attempts from %SystemRoot% or %ProgramFiles% directories, and outbound connections to IP addresses associated with known C2 domains like *.suppobox[.]com or *.menupass[.]org. Registry keys for persistence may appear under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names mimicking legitimate services (e.g., "WindowsUpdateService"). Network IOCs include User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; WOW64) rv:40.0" and HTTP POST requests to /api/update endpoints with base64-encoded payloads.

☠️ Risk & Impact

SuppoBox poses a high risk due to its stealthy data exfiltration capabilities, enabling long-term theft of intellectual property, classified military documents, and personally identifiable information (PII). Affected sectors include aerospace, defense, telecommunications, healthcare, and government agencies, particularly in Japan, South Korea, the United States, and Europe. Financial losses are substantial, with the 2017 MSP compromise causing an estimated $1 billion in damage across multiple supply-chain victims, as noted in U.S. Congressional testimony.

🛡️ Mitigation

Recommended defenses include implementing application whitelisting to block unauthorized DLLs, deploying endpoint detection and response (EDR) tools with behavioral analytics for side-loading anomalies, and patching known vulnerabilities in Apache Struts, JBoss, and Oracle WebLogic. Network monitoring should focus on unusual outbound HTTPS traffic to uncategorized domains, and organizations should adopt the MITRE ATT&CK mitigation strategies M1040 (Behavior Prevention on Endpoint) and M1031 (Network Intrusion Prevention). Regular threat intelligence feeds from FireEye and CrowdStrike provide updated IOCs and YARA rules for SuppoBox detection.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.