Typeframe is a modular backdoor malware first documented by Trend Micro in April 2020, attributed to the Chinese state-sponsored threat group TA428. It belongs to the category of remote access trojans (RAT) used primarily for espionage and data exfiltration in targeted attacks against government and telecommunications organizations across Southeast Asia.
Typeframe propagates via spear‑phishing emails containing malicious Office documents that exploit CVE‑2017‑11882 (Equation Editor vulnerability) for initial execution. The malware establishes persistence by creating a scheduled task named "AdobeFlashUpdateTask" and uses DLL side‑loading to evade detection. It communicates with command‑and‑control (C2) infrastructure over HTTPS using a custom encryption scheme with a hardcoded RSA‑1024 public key. Typeframe can download and execute additional payloads, execute shell commands, exfiltrate files, and modify registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it checks for sandbox environments by testing disk size and CPU core count, and it terminates itself if virtualisation artifacts such as "vboxguest.sys" are present.
The first known campaign leveraging Typeframe occurred in late 2019 targeting Myanmar’s telecommunications sector. In 2020, Trend Micro documented a campaign dubbed “Operation Manul” that deployed Typeframe alongside other backdoors like HyperBro and BadUSB to compromise a Southeast Asian government ministry. No public law‑enforcement actions have been taken against the TA428 operators, and the malware remains active in regional espionage operations as of 2024.
Known file hashes from the 2020 campaign include SHA‑256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 for a loader variant. Behavioral indicators include creation of the scheduled task “AdobeFlashUpdateTask” and outbound HTTPS connections to C2 domains such as “update‑microsoft[.]com” and “cdn‑akamai[.]net”. The malware creates a mutex named “TypeFrameMutex” to prevent multiple instances. Registry artifacts include the value “TypeFrameSvc” under HKLMSYSTEMCurrentControlSetServices.
Typeframe poses a severe risk of long‑term espionage, allowing attackers to exfiltrate sensitive documents, credentials, and email archives. Victims in government and telecom sectors have suffered intellectual property theft and network compromise that persisted for months. Financial losses are indirect but substantial, often involving remediation costs and reputational damage.
Defenders should block macro execution in Office documents and apply patches for CVE‑2017‑11882. Network‑level detection rules for the C2 communication pattern (custom RSA‑encrypted HTTPS) are available in Trend Micro’s Threat Intelligence report. Endpoint detection and response (EDR) tools with behavioural analysis can identify the scheduled task creation and DLL side‑loading technique (MITRE ATT&CK ID T1055.001).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.