TYPEFRAME

Malware

⚠️ Overview

Typeframe is a modular backdoor malware first documented by Trend Micro in April 2020, attributed to the Chinese state-sponsored threat group TA428. It belongs to the category of remote access trojans (RAT) used primarily for espionage and data exfiltration in targeted attacks against government and telecommunications organizations across Southeast Asia.

🔧 Technical Capabilities

Typeframe propagates via spear‑phishing emails containing malicious Office documents that exploit CVE‑2017‑11882 (Equation Editor vulnerability) for initial execution. The malware establishes persistence by creating a scheduled task named "AdobeFlashUpdateTask" and uses DLL side‑loading to evade detection. It communicates with command‑and‑control (C2) infrastructure over HTTPS using a custom encryption scheme with a hardcoded RSA‑1024 public key. Typeframe can download and execute additional payloads, execute shell commands, exfiltrate files, and modify registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it checks for sandbox environments by testing disk size and CPU core count, and it terminates itself if virtualisation artifacts such as "vboxguest.sys" are present.

📜 History & Notable Incidents

The first known campaign leveraging Typeframe occurred in late 2019 targeting Myanmar’s telecommunications sector. In 2020, Trend Micro documented a campaign dubbed “Operation Manul” that deployed Typeframe alongside other backdoors like HyperBro and BadUSB to compromise a Southeast Asian government ministry. No public law‑enforcement actions have been taken against the TA428 operators, and the malware remains active in regional espionage operations as of 2024.

🔍 Detection Indicators

Known file hashes from the 2020 campaign include SHA‑256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 for a loader variant. Behavioral indicators include creation of the scheduled task “AdobeFlashUpdateTask” and outbound HTTPS connections to C2 domains such as “update‑microsoft[.]com” and “cdn‑akamai[.]net”. The malware creates a mutex named “TypeFrameMutex” to prevent multiple instances. Registry artifacts include the value “TypeFrameSvc” under HKLMSYSTEMCurrentControlSetServices.

☠️ Risk & Impact

Typeframe poses a severe risk of long‑term espionage, allowing attackers to exfiltrate sensitive documents, credentials, and email archives. Victims in government and telecom sectors have suffered intellectual property theft and network compromise that persisted for months. Financial losses are indirect but substantial, often involving remediation costs and reputational damage.

🛡️ Mitigation

Defenders should block macro execution in Office documents and apply patches for CVE‑2017‑11882. Network‑level detection rules for the C2 communication pattern (custom RSA‑encrypted HTTPS) are available in Trend Micro’s Threat Intelligence report. Endpoint detection and response (EDR) tools with behavioural analysis can identify the scheduled task creation and DLL side‑loading technique (MITRE ATT&CK ID T1055.001).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.