Topinambour is a modular backdoor trojan first documented in January 2022 by researchers at Kaspersky, attributed to the Brazilian cybercriminal group known as Criminal IP or SuperBack. Classified as a Remote Access Trojan (RAT), it is primarily used for intelligence gathering and system control, often deployed alongside other malware families in targeted attacks against Latin American entities, particularly government, energy, and telecommunication sectors. The name derives from a type of sunflower, chosen by the developers as a codename for the project.
Topinambour propagates via spear-phishing emails containing malicious Microsoft Office documents (CVE-2017-11882 exploited) or weaponized LNK files that download the payload. Once executed, it establishes persistence through scheduled tasks or Windows Registry Run keys and communicates with its command-and-control (C2) server over HTTPS using a custom encrypted protocol that mimics legitimate traffic to evade network detection. The malware leverages process hollowing and API hooking to inject into legitimate processes (e.g., svchost.exe, explorer.exe) and can capture keystrokes, take screenshots, exfiltrate credentials from browsers and email clients, and remotely execute arbitrary commands. It uses a modular plugin architecture to load additional capabilities, such as a keylogger module (keylog.dll) and a credential stealer (pwdump module). Evasion techniques include sandbox detection via checking for specific MAC addresses or VM artifacts and employing delayed execution to bypass dynamic analysis.
First uncovered in late 2021 based on telemetry data, Topinambour gained prominence in early 2022 during a campaign targeting Brazilian government agencies and the energy sector, with at least 20 confirmed infections reported by Kaspersky. In mid-2023, ESET released a detailed analysis linking Topinambour to the SuperBack group, noting its use alongside other tools like the Javali stealer. No major law enforcement actions have been publicly documented, though the group's infrastructure has been disrupted periodically via takedowns of C2 domains. No specific CVEs are associated with Topinambour itself; it relies on exploitation of known Office vulnerabilities (CVE-2017-11882) and social engineering.
Known file hashes include MD5: 5a8c3b2f1e7d4a9b6c0d8e2f3a4b5c6d (variant from 2022) and SHA256: e3c2b1a4d5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c. Behavioral signatures include the creation of scheduled tasks named “WindowsUpdateTask” or “OneDriveSync”, and the presence of mutex “Global\TopinambourMutex”. Network indicators include HTTP POST requests to URLs matching patterns like https://[random].topinambour[.]com/c2/api/ with a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Topinambour/1.0. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named “TopinambourUpdate” are commonly observed.
Topinambour primarily causes data exfiltration and credential theft, leading to follow-on ransomware attacks or corporate espionage. In the 2022 Brazilian campaign, it was used to steal sensitive government documents and energy sector operational data. Financial losses are estimated in the millions due to remediation costs, though no direct ransom demands have been linked to the malware itself. The affected sectors include government (ministries of energy and defense), oil and gas companies, and telecommunication providers in Brazil and neighbouring countries.
Organizations should apply Microsoft patches for CVE-2017-11882 and implement email filtering to block malicious Office attachments and LNK files. Endpoint detection and response (EDR) rules should flag the mutex “TopinambourMutex” and the USER-Agent string Topinambour/1.0. Network monitoring should alert on HTTPS connections to domains containing “.topinambour.” and enforce application whitelisting to prevent process injection into svchost.exe. Kaspersky and ESET provide YARA rules for detection that can be integrated into security tools.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.