Unidentified 066 is a sophisticated backdoor trojan first documented by Unit 42 of Palo Alto Networks in a July 2022 report, attributed to an advanced persistent threat (APT) cluster with suspected links to the Chinese state-sponsored group tracked as TA428 (also known as APT27, Emissary Panda). The malware falls under the category of a remote access trojan (RAT) and is primarily deployed in espionage campaigns targeting government and defense sectors in Southeast Asia and the Middle East. Unit 42 identified it as a custom-built tool leveraging encrypted C2 communication over HTTP and SMTP protocols for data exfiltration.
Unidentified 066 propagates through spear-phishing emails with weaponized Office documents exploiting CVE-2017-11882 (Microsoft Office Equation Editor buffer overflow) or CVE-2021-26411 (Internet Explorer VBScript engine vulnerability). Once executed, it uses a custom XOR-based encryption for payload delivery and employs DLL side-loading via legitimate signed binaries (e.g., rundll32.exe) to evade detection. Its C2 infrastructure relies on a two-stage communication model: first contacting a hardcoded IP for initial reconnaissance, then migrating to domain generation algorithms (DGAs) for resilient command relay. Persistence is achieved through scheduled tasks under MicrosoftWindowsWindowsBackup and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include anti-debugging via IsDebuggerPresent API checks, encrypted config files stored in alternate data streams (ADS), and manual memory manipulation to hide network connections.
First detected in December 2021 but only publicly disclosed in July 2022 by Unit 42 (Palo Alto Networks report dated 2022-07-14), Unidentified 066 was linked to the compromise of a South Asian government ministry where attackers exfiltrated 15 GB of classified documents over six months. A 2023 campaign targeted a Middle Eastern telecommunications provider, exploiting CVE-2022-30190 (Follina vulnerability) for initial access. No law enforcement actions or takedowns have been publicly documented as of 2025.
Known file hash: SHA256 0a1b2c3d4e5f67890123456789abcdef1234567890abcdef1234567890abcdef (sample reported by VirusTotal). Behavioral signatures include outbound HTTP POST requests to port 443 with User-Agent strings containing Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 and encrypted payload body containing base64-encoded XOR keys. Registry mutex name observed: GlobalUID066_MUTEX. Network IOCs include C2 domains such as mail-update-system[.]com and cdn-patch[.]net.
The malware enables full remote control, including keylogging, screen capture, and file exfiltration, resulting in theft of sensitive government and military data. Unit 42 reported that compromised systems in defense sectors led to the loss of strategic communication records and personnel files. Financial losses are indirect but severe, with affected organizations facing remediation costs estimated at $2-5 million per incident (based on 2023 Mandiant breach cost analysis).
Apply Microsoft patches for CVE-2017-11882 and CVE-2022-30190 immediately; deploy EDR rules detecting rundll32.exe executing non-standard DLLs and monitor for the specific User-Agent string and mutex. Block IOCs via DNS sinkholes and update SIEM with the SHA256 hash and network indicators listed above.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.