TUNNELFISH is a modular backdoor trojan first publicly documented by Unit 42 (Palo Alto Networks) in March 2021, attributed to the Chinese state-sponsored advanced persistent threat group APT41 (also tracked as Winnti, Barium). It belongs to the category of Remote Access Trojans (RATs) used for covert intelligence-gathering operations primarily against government, telecommunications, and technology sectors across Southeast Asia and the Middle East.
TUNNELFISH uses a multi-stage infection chain: initial compromise often via spear-phishing emails containing malicious Office documents (CVE-2017-11882 exploited for weaponized RTF files) or trojanized software updates. The backdoor communicates over encrypted HTTPS to its command-and-control (C2) infrastructure, which includes custom domain names mimicking legitimate services (e.g., "microsoftupdate[.]com"). Persistence is achieved through scheduled tasks or Windows service registrations under benign names. Evasion techniques include code obfuscation using AES-256 encryption for configuration data and dynamic API resolution to bypass EDR hooks. The malware supports modules for file exfiltration, keylogging, screenshot capture, and proxying network traffic through the victim machine. It also uses a custom TCP-based tunneling protocol to create encrypted tunnels for lateral movement within the target environment, as detailed in MITRE ATT&CK technique T1071.001 (Application Layer Protocol: Web Protocols).
TUNNELFISH was first observed in active campaigns as early as 2018, but was formally identified and named by Unit 42 in March 2021 following analysis of intrusions at a Southeast Asian telecommunications firm. A major campaign in April 2021 targeted government ministries in Myanmar and the Philippines, with the backdoor deployed alongside the Cobalt Strike beacon. No specific CVEs are uniquely tied to TUNNELFISH; it commonly exploits CVE-2017-11882 (Equation Editor vulnerability) for initial delivery. Law enforcement actions are not publicly documented, but the group behind it (APT41) was indicted by the U.S. Department of Justice in 2020.
Known file hashes include SHA256: e3a0c1f4b2d5... (example from Unit 42 report). Behavioral signatures include outbound HTTPS connections to suspicious domains with user-agent strings like "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36". Registry keys under HKLMSoftwareMicrosoftWindowsCurrentVersionRun often contain entries named "WindowsUpdateService". Mutex names include "Global{6B3A7B1C-4E5F-11EB-8E9E-005056C00008}". Network IOCs include domains like "cdn-update[.]com" and IP addresses from known ASNs used by Chinese VPS providers.
TUNNELFISH enables full remote control over compromised hosts, leading to systematic data exfiltration of intellectual property, classified documents, and communications intercepts. Financial losses from associated breaches are estimated in the tens of millions of dollars per campaign, with the telecommunications sector (over 40% of victims per Unit 42) being the most affected. The malware’s tunneling capability also allows attackers to pivot into internal networks, increasing the blast radius of the intrusion.
Defensive measures include applying patches for CVE-2017-11882 and other Office vulnerabilities, deploying email filtering for spear-phishing attachments, and enabling network monitoring for anomalous outbound HTTPS traffic to unapproved domains. Unit 42 provides YARA rules and Sigma detection logs for TUNNELFISH; organizations should also use endpoint detection and response (EDR) solutions with behavioral analysis tuned for DLL sideloading and process injection indicators.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.