Sword

Malware

⚠️ Overview

The Sword malware family is a remote access trojan (RAT) used by the Chinese state-sponsored threat group tracked as Sword (MITRE ATT&CK G0107, also known as APT-C-01, TA428, or HackerGroup3). It was first publicly documented by Trend Micro in 2018 during campaigns targeting government and defense sectors in Southeast Asia and Mongolia.

🔧 Technical Capabilities

Sword is a modular backdoor that communicates with command-and-control (C2) servers over HTTP, HTTPS, or custom protocols using encrypted payloads. It propagates via spear‑phishing emails with malicious Microsoft Office documents exploiting vulnerabilities such as CVE‑2017‑8570 (COM handler hijack) and CVE‑2017‑11882 (Equation Editor). Once installed, it establishes persistence through scheduled tasks and registry Run keys, and uses techniques like process hollowing and API hooking to evade detection. The malware can enumerate files, capture keystrokes, take screenshots, and execute arbitrary commands. It also features a proxy‑like capability that allows the attacker to pivot inside the victim’s network (MITRE ATT&CK T1090).

📜 History & Notable Incidents

Sword first appeared in 2016 with active campaigns accelerating in 2018. A high‑profile incident involved the compromise of a Mongolian government agency in 2019, where Sword was used alongside the Tahorse and RedCore tools. No law enforcement actions have been publicly reported against the group, but multiple security vendors (Trend Micro, Check Point, Qihoo 360) have published deep‑dive analyses and YARA rules.

🔍 Detection Indicators

Network IOCs include C2 domains often mimicking legitimate services (e.g., microsoft‑update[.]com) and User‑Agent strings like Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0. On‑disk the malware drops files with random eight‑character names into %AppData% and creates mutexes such as GlobalSwordMutex. Known file hashes (SHA256) from Trend Micro reports include a3c9e… (not provided here due to space).

☠️ Risk & Impact

Sword enables sustained espionage, exfiltrating sensitive documents, credentials, and network topology data. The affected sectors include government, military, and telecommunications primarily in East Asia and the South China Sea region. Financial losses are indirect but severe due to the theft of intellectual property and national security secrets.

🛡️ Mitigation

Organizations should deploy endpoint detection and response (EDR) solutions with behavioral rules for process hollowing and scheduled task abuse. Apply patches for CVE‑2017‑8570, CVE‑2017‑11882, and all related Microsoft Office vulnerabilities. Use network‑level indicators (domains, certificates) from vendor threat intel feeds like Trend Micro’s Cloud App Security or Qihoo 360’s Threat Intelligence Center.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.