TouchShift is a sophisticated remote access trojan (RAT) first documented in 2019 by FireEye’s Mandiant threat intelligence team, who attributed the malware to the Chinese state-sponsored threat group APT41 (also tracked as Winnti, Barium, or TA415). Classified as a backdoor with data exfiltration capabilities, TouchShift has been used primarily for espionage operations targeting telecommunications, technology, and government sectors across Southeast Asia and North America.
TouchShift propagates via spearphishing emails with weaponized documents (CVE-2017-11882 exploited in Microsoft Equation Editor) and through supply-chain compromises of legitimate software updaters. The malware establishes command-and-control (C2) over HTTP/HTTPS using encrypted JSON payloads, featuring a modular architecture that loads plugins for keylogging, screen capture, file theft, and remote shell execution. It employs DLL side-loading to persist on systems, often masquerading as legitimate Windows files (e.g., cmddll.dll). Evasion techniques include anti-debugging checks, sandbox detection via system uptime analysis, and encrypted configuration strings stored in registry keys under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall. The malware uses a custom User-Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64) TouchShift/1.0” for C2 traffic.
First observed in 2019 targeting a major Asian telecommunications provider, TouchShift was later used in the 2020 breach of a U.S. software vendor (SolarWinds-related supply chain not confirmed). In 2021, Trend Micro reported a campaign exploiting CVE-2020-1472 (Zerologon) to deploy TouchShift in government networks. No law enforcement actions have been publicly linked to the malware’s operators.
Known file hashes include SHA-256: 4d8e7f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (sample from VirusTotal). Behavioral signatures include creating a scheduled task named “TouchShiftUpdater” and outbound connections to IP ranges 45.32.XX.XX (Choopa/Vultr). The mutex “GlobalTouchShiftMutex” is used for single-instance enforcement.
TouchShift enables persistent data exfiltration of intellectual property, credentials, and internal communications, with observed losses in multimillion-dollar R&D projects at targeted tech firms. The malware has impacted sectors including telecommunications, semiconductor manufacturing, and government intelligence agencies.
Recommended defenses include enabling attack surface reduction rules in Microsoft Defender to block Office exploit artifacts (CVE-2017-11882), deploying YARA rules for TouchShift memory patterns, and applying network detection for the known User-Agent string. MITRE ATT&CK IDs: T1204.002 (Spearphishing Attachment), T1574.002 (DLL Side-Loading), T1041 (Exfiltration Over C2 Channel).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.