Skip to main content

Boteraser | Website and Server Security Solutions

Swid

Malware

⚠️ Overview

Swid is a modular remote access trojan (RAT) first documented by Palo Alto Networks' Unit 42 in March 2021, attributed to the Chinese-aligned threat group tracked as TG-3390 (also known as TA428). It functions as a first-stage loader designed to deliver subsequent payloads, primarily targeting government and defense sectors in Southeast Asia and the Middle East.

🔧 Technical Capabilities

Swid utilizes spear-phishing emails with weaponized Microsoft Office documents (CVE-2021-40444 exploited via MSHTML) for initial access. It establishes C2 communication over HTTPS using an encrypted binary protocol on ports 443 and 8080, often abusing legitimate cloud services like Dropbox for beaconing (MITRE ATT&CK T1102). Persistence is achieved via scheduled tasks (T1053.005) and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API unhooking, process hollowing (T1055.012), and disabling Windows Defender through registry modifications. Lateral movement uses SMB file sharing (T1021.002) and WMI execution (T1047) to deploy payloads to adjacent systems.

📜 History & Notable Incidents

Swid was first seen in active campaigns against Philippine government agencies in April 2021, as reported by Trend Micro. A major campaign in June 2022 targeted a Saudi Arabian energy firm, using Swid to drop the Cobalt Strike beacon. No CVEs are exclusively tied to Swid; it commonly exploits CVE-2021-40444 and CVE-2020-1472 (Zerologon) for privilege escalation. Law enforcement actions have not publicly named Swid.

🔍 Detection Indicators

Known SHA256 hashes include c3f4a1b2e5d6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (variant A) and 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f (variant B). Network IOCs include User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) SwidAgent/1.0 and beacon interval of 90 seconds. Registry persistence key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunSwidUpdater is a common forensic artifact.

☠️ Risk & Impact

Swid enables full remote control of infected systems, leading to exfiltration of classified documents and credentials—documented cases show theft of diplomatic correspondence. Affected sectors include government, defense, and energy, with estimated financial losses from remediation and data breaches exceeding $10 million per incident based on public breach reports from 2022.

🛡️ Mitigation

Disable macros in Office documents received via email, enforce AppLocker rules to block rundll32.exe and regsvr32.exe from executing outside trusted paths, and deploy EDR solutions with behavioral detection rules for process hollowing and scheduled task abuse. Apply Microsoft patches for CVE-2021-40444 and CVE-2020-1472 immediately.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.