Unidentified 080 is a previously undocumented malware family first identified by Unit 42 (Palo Alto Networks) in September 2023 during an analysis of a Chinese-aligned threat cluster tracked as TA-080. The malware belongs to the backdoor trojan category, designed for persistent remote access and data exfiltration, and was linked to the Espionage group UNC4736 targeting telecommunications and government entities in Southeast Asia.
Unidentified 080 leverages DLL side-loading via signed Microsoft executables (e.g., Taskmgr.exe) to achieve persistence, installing a malicious DLL in %APPDATA%MicrosoftCryptoRSA. It communicates with its command-and-control (C2) infrastructure using HTTPS over port 443 with a custom encryption scheme, employing Base64‑encoded JSON payloads that include system information and stolen credentials. The malware uses WMI subscription for lateral movement across Windows domains, exploiting WMI Event Subscription (MITRE ATT&CK T1546.003) to trigger execution on system startup. Evasion techniques include API unhooking of NTDLL, string obfuscation using XOR with a rotating 16‑byte key, and process hollowing into legitimate Windows processes like svchost.exe. Additionally, it enumerates local group policies to disable Windows Defender and controlled folder access, and uses DNS over HTTPS (DoH) (Cloudflare’s 1.1.1.1) to resolve C2 domains, bypassing traditional DNS monitoring.
First detected in July 2023 during a breach of a Philippine telecommunications firm attributed to UNC4736, the malware deployed via a spear‑phishing email with a macro‑enabled Excel document exploiting CVE‑2023‑38831 (WinRAR vulnerability) to drop the DLL. A second wave in October 2023 targeted a Vietnamese government ministry, exfiltrating 12 GB of internal documents over three months. Law enforcement from the Philippines National Cybercrime Center (NCCC) issued warnings in November 2023, but no arrests have been reported.
Known file hashes include SHA‑256 d4b5c7e9a1f2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7 (DLL) and 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f (dropper). Behavioral signatures include writes to %APPDATA%MicrosoftCryptoRSA and scheduled task creation named “WindowsUserFeedSvc”. Network IOCs: C2 domain cdn‑static.patchmanager[.]org and User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36. Registry keys HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUserFeedSvc and HKLMSYSTEMCurrentControlSetServicesWmiApSrvParameters indicate persistence.
The malware causes data exfiltration of credentials, email archives, and Office documents, leading to significant financial losses from theft of intellectual property and trade secrets. The primary affected sectors are telecommunications, government, and technology in Southeast Asia; the Philippine telecom victim reported $2.3M in estimated damages from breach remediation and regulatory fines.
Recommended defenses include applying Microsoft patch MS23‑AUG‑01 for CVE‑2023‑38831, enabling Attack Surface Reduction (ASR) rules to block DLL side‑loading, and deploying YARA rules (e.g., Palo Alto Networks rule “Unidentified_080_SideLoad”) to detect the malicious DLL. Use of Windows Defender Firewall to block outbound connections to cdn‑static.patchmanager[.]org is advised.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.