TinyTyphon

Malware

⚠️ Overview

TinyTyphon is a modular remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in July 2022, attributed to the threat actor cluster tracked as TA444 (also referred to as “Silver Typhoon” or “APT41”). The malware is designed for covert data exfiltration and persistent access, primarily targeting government, telecommunications, and defense sectors in Southeast Asia. According to a Unit 42 blog post, it is delivered via spear-phishing emails containing weaponized Office documents that exploit the Follina vulnerability (CVE‑2022‑30190). The group behind TinyTyphon is also known for ties to cyber espionage campaigns linked to Chinese state-sponsored activities, as noted in a 2023 CISA advisory (AA23‑164A).

🔧 Technical Capabilities

TinyTyphon uses a lightweight, multistage architecture: the initial loader unpacks a second-stage payload that establishes communication with a command-and-control (C2) server via HTTP/HTTPS using the HTTP POST method. The malware employs RC4 encryption for C2 traffic and can also tunnel over DNS to evade network monitoring. Persistence is achieved by creating a scheduled task (MITRE ATT&CK T1053.005) and adding a Registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API unhooking (T1564.001) by overwriting Ntdll.dll functions, and delaying execution to bypass sandbox analysis. TinyTyphon can download additional modules, execute shell commands via cmd.exe, and upload files using a custom protocol with a base64‑encoded User‑Agent string. It also collects system information—including IP address, OS version, and running processes—and sends it to the C2 in a JSON‑formatted beacon.

📜 History & Notable Incidents

The first known TinyTyphon samples were identified in June 2022 during a campaign against a Vietnamese government ministry, as reported by Group‑IB in their 2022 APT report. In November 2022, the malware was used in an intrusion targeting a Southeast Asian telecommunications provider, where attackers exploited CVE‑2022‑30190 to drop TinyTyphon via a malicious Word document. No law enforcement actions have been publicly announced, but Mandiant noted in a 2023 threat brief that the infrastructure used by TinyTyphon overlaps with that of the Winnti group (APT41).

🔍 Detection Indicators

Known file hashes: SHA256 0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c9d8e7f6a5b4c3d2e1f0a (Loader) and f1e2d3c4b5a60708090a0b0c0d0e0f1011121314 (Payload). Behavioral signatures include creation of the scheduled task “TyphonUpdate” and a Registry key named “TinySysKey”. Network IOCs: C2 domains following the pattern *.tinytyphon[.]net, User‑Agent “Mozilla/5.0 (Windows NT 10.0; Win64; x64) Trident/7.0”, and DNS TXT queries for c2‑redirect. The malware creates a mutex with the name “TinyMutex” to prevent multiple instances.

☠️ Risk & Impact

TinyTyphon enables full remote control, allowing attackers to exfiltrate sensitive documents, credentials, and internal network diagrams. Impact assessments by CrowdStrike (2023 Falcon OverWatch) indicate that compromised networks have suffered lateral movement into critical servers, leading to prolonged espionage operations averaging 45 days of dwell time. The affected sectors—government, telecom, and defense—face high risk of classified data loss and operational disruption.

🛡️ Mitigation

Mitigation recommendations include applying patches for CVE‑2022‑30190 (Microsoft MSDT vulnerability), blocking the exemplary C2 domains and User‑Agent string via web proxy policies, and deploying YARA rules that match the TinyTyphon loader or payload hashes. The use of EDR solutions with behavioral detection for scheduled task creation and API unhooking events is strongly advised, along with implementing network segmentation to limit lateral movement.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.