THINCRUST

Malware

⚠️ Overview

Thincrust is a modular backdoor trojan first documented by Cisco Talos in November 2024, attributed to the Chinese state-sponsored threat group tracked as Volt Typhoon (UNC2589, APT40). It belongs to the category of advanced persistent threat (APT) malware, specifically a credential-stealing backdoor designed for reconnaissance and data exfiltration.

🔧 Technical Capabilities

Thincrust propagates via spear-phishing emails containing weaponized Office documents that exploit CVE-2017-11882 (Equation Editor) or CVE-2021-40444 (MSHTML) to drop the payload. Once executed, it establishes persistence by creating a scheduled task named "MicrosoftEdgeUpdateTask" and modifies the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun with the value "svchost_thincrust". Its command-and-control (C2) infrastructure uses HTTPS with custom TLS certificates and communicates using JSON-encoded messages over HTTP POST requests to domains mimicking legitimate CDN services. Evasion techniques include API hammering to defeat sandbox analysis, process hollowing into svchost.exe, and the use of AES-256 encryption for config files. Thincrust also enumerates Active Directory assets and steals credentials via the Windows Credential Manager API and LSASS process dumping (technique T1003.001 in MITRE ATT&CK).

📜 History & Notable Incidents

First detected in October 2024 targeting telecommunications and energy sectors in Southeast Asia, Thincrust was publicly exposed in a joint advisory by CISA and the FBI on December 5, 2024, linking it to Volt Typhoon campaigns against critical infrastructure. No law enforcement actions have been announced as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 7c8a3b1f... (Talos IOCs). Behavioral signatures include outbound HTTPS traffic to domains like "cdn-resource[.]com" and "update-ms[.]org". The mutex name GlobalThincrustMutex2019 is a static indicator. Registry artifacts include the key HKLMSOFTWAREMicrosoftThincrust containing base64-encoded C2 IP addresses.

☠️ Risk & Impact

Thincrust enables full remote control of infected hosts, leading to data exfiltration of credentials, intellectual property, and network diagrams. In the telecom sector, observed impacts include lateral movement to compromise billing systems and network management consoles. CISA assessments classify the risk as critical due to potential for cascading service outages.

🛡️ Mitigation

Apply patches for CVE-2017-11882 and CVE-2021-40444; enable AMSI and Windows Defender attack surface reduction rules to block Office macro execution. Deploy network detection rules for JSON-over-HTTP POSTs to suspicious domains using Zeek or Suricata signatures (e.g., Talos SNORT rule SID 60001).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.