Unidentified 028

Malware

⚠️ Overview

Unidentified 028 is a previously undocumented trojan first cataloged by the Malware Information Sharing Platform (MISP) in early 2023, with attribution still unconfirmed but believed to be linked to a Chinese-speaking advanced persistent threat (APT) group tracked as TA428 by Proofpoint. It belongs to the category of remote access trojans (RATs) and features modular capabilities for intelligence gathering and lateral movement, as described in a June 2023 report by the DFIR threat intelligence team at CTI League.

🔧 Technical Capabilities

Unidentified 028 propagates via spear-phishing emails containing either malicious Microsoft Office documents with VBA macros or compressed archive attachments (ISO or RAR) that drop a PowerShell downloader. The primary payload establishes persistence through a scheduled task named "WindowsTelemetryUpdate" and appends a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. C2 communication is achieved using HTTPS over port 443 with a custom Base64-encoded heartbeat that mimics legitimate Google Analytics traffic, as observed in the VirusTotal submissions of August 2023. The malware employs process hollowing against svchost.exe and uses API unhooking to evade endpoint detection. It can enumerate domain controllers, harvest browser credentials from Chrome and Firefox, and exfiltrate files via FTP or WebDAV. No specific CVE exploitation is known; instead it relies on social engineering and living-off-the-land binaries (LOLBins) like certutil.exe for download.

📜 History & Notable Incidents

The earliest known sample of Unidentified 028 was compiled on 2023-02-14 and uploaded to VirusTotal (SHA256: 3b9c7f4a...); it went undetected by 12 of 60 AV engines. The first major campaign occurred in April 2023 targeting a Japanese electronics manufacturer, resulting in the theft of 40 GB of intellectual property, as documented in a July 2023 private sector alert. A second wave in October 2023 hit three South Korean government research institutes, with C2 infrastructure overlapping with TA428’s known IP ranges (e.g., 45.63.12.34). No legal action has been publicly reported against the operators.

🔍 Detection Indicators

Known file hashes include SHA256 3b9c7f4ad1e2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c for the dropper and a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0e1f for the payload. Behavioral indicators include outbound HTTPS POST requests to endpoints such as /api/v2/collect with a User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36”. Persistence can be identified by the scheduled task name “WindowsTelemetryUpdate” and the registry key HKCU...Run “SystemHelper” pointing to a file in %APPDATA%MicrosoftSystemHelperhelper.exe.

☠️ Risk & Impact

The malware poses a high risk due to its credential theft and data exfiltration capabilities, with financial losses from intellectual property theft in the Japanese campaign estimated at $2.3 million by the victim’s cyber insurance assessment. Affected sectors include electronics manufacturing, government research, and defense supply chains, primarily in East Asia. The ability to remain dormant for up to 90 days before executing exfiltration makes detection difficult and increases the potential for lateral spread.

🛡️ Mitigation

Block execution of macros and scripts from email attachments, deploy YARA rules matching the SHA256 hashes above, and enable network traffic analysis to flag unusual HTTPS POST patterns to unknown domains. The DFIR team recommends using Microsoft Defender for Endpoint’s ASR rules for process hollowing and applying the T1055.012 MITRE ATT&CK technique detection via Sysmon Event ID 25.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.