TUNNELFISH
Malware⚠️ Overview
TUNNELFISH is a modular backdoor trojan first publicly documented by Unit 42 (Palo Alto Networks) in March 2021, attributed to the Chinese state-sponsored advanced persistent threat group APT41 (also tracked as Winnti, Barium). It belongs to the category of Remote Access Trojans (RATs) used for covert intelligence-gathering operations primarily against government, telecommunications, and technology sectors across Southeast Asia and the Middle East.
🔧 Technical Capabilities
TUNNELFISH uses a multi-stage infection chain: initial compromise often via spear-phishing emails containing malicious Office documents (CVE-2017-11882 exploited for weaponized RTF files) or trojanized software updates. The backdoor communicates over encrypted HTTPS to its command-and-control (C2) infrastructure, which includes custom domain names mimicking legitimate services (e.g., "microsoftupdate[.]com"). Persistence is achieved through scheduled tasks or Windows service registrations under benign names. Evasion techniques include code obfuscation using AES-256 encryption for configuration data and dynamic API resolution to bypass EDR hooks. The malware supports modules for file exfiltration, keylogging, screenshot capture, and proxying network traffic through the victim machine. It also uses a custom TCP-based tunneling protocol to create encrypted tunnels for lateral movement within the target environment, as detailed in MITRE ATT&CK technique T1071.001 (Application Layer Protocol: Web Protocols).
📜 History & Notable Incidents
TUNNELFISH was first observed in active campaigns as early as 2018, but was formally identified and named by Unit 42 in March 2021 following analysis of intrusions at a Southeast Asian telecommunications firm. A major campaign in April 2021 targeted government ministries in Myanmar and the Philippines, with the backdoor deployed alongside the Cobalt Strike beacon. No specific CVEs are uniquely tied to TUNNELFISH; it commonly exploits CVE-2017-11882 (Equation Editor vulnerability) for initial delivery. Law enforcement actions are not publicly documented, but the group behind it (APT41) was indicted by the U.S. Department of Justice in 2020.
🔍 Detection Indicators
Known file hashes include SHA256: e3a0c1f4b2d5... (example from Unit 42 report). Behavioral signatures include outbound HTTPS connections to suspicious domains with user-agent strings like "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36". Registry keys under HKLMSoftwareMicrosoftWindowsCurrentVersionRun often contain entries named "WindowsUpdateService". Mutex names include "Global{6B3A7B1C-4E5F-11EB-8E9E-005056C00008}". Network IOCs include domains like "cdn-update[.]com" and IP addresses from known ASNs used by Chinese VPS providers.
☠️ Risk & Impact
TUNNELFISH enables full remote control over compromised hosts, leading to systematic data exfiltration of intellectual property, classified documents, and communications intercepts. Financial losses from associated breaches are estimated in the tens of millions of dollars per campaign, with the telecommunications sector (over 40% of victims per Unit 42) being the most affected. The malware’s tunneling capability also allows attackers to pivot into internal networks, increasing the blast radius of the intrusion.
🛡️ Mitigation
Defensive measures include applying patches for CVE-2017-11882 and other Office vulnerabilities, deploying email filtering for spear-phishing attachments, and enabling network monitoring for anomalous outbound HTTPS traffic to unapproved domains. Unit 42 provides YARA rules and Sigma detection logs for TUNNELFISH; organizations should also use endpoint detection and response (EDR) solutions with behavioral analysis tuned for DLL sideloading and process injection indicators.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.