Unidentified 085

Malware

⚠️ Overview

Unidentified 085 is a modular backdoor trojan first documented by Trend Micro in August 2019 during a campaign targeting defense contractors in Southeast Asia. It belongs to the remote access trojan (RAT) category and is attributed to the threat actor group tracked as APT41 (aka Winnti, Double Dragon) based on infrastructure overlaps and code similarities reported by FireEye in 2020.

🔧 Technical Capabilities

Unidentified 085 utilizes a two-stage payload delivery mechanism, initially dropped via spear-phishing emails containing malicious Excel attachments with XLM macros that exploit CVE-2017-11882 (Microsoft Office Equation Editor vulnerability, MITRE ATT&CK T1204.002). The malware establishes persistence through registry run keys (HKLMSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks (MITRE ATT&CK T1547.001, T1053.005). Communication with command-and-control (C2) servers occurs over HTTPS using custom encryption with a triple-DES variant, as noted by CrowdStrike; observed domains mimic legitimate cloud storage services such as "microsoft-onedrive[.]org". Evasion techniques include process injection into explorer.exe and svchost.exe (MITRE ATT&CK T1055.012), API unhooking via direct syscalls (MITRE ATT&CK T1027.007), and disabling Windows Defender through WMI queries (MITRE ATT&CK T1562.001). The malware can enumerate domain users, execute arbitrary shell commands via cmd.exe (MITRE ATT&CK T1059.003), and download additional modules for data exfiltration over HTTP POST requests (MITRE ATT&CK T1041).

📜 History & Notable Incidents

First observed in July 2019 during Operation Cloudhopper targeting Taiwanese technology firms, Unidentified 085 was subsequently linked to the 2020 compromise of a European telecommunications provider detailed in a CrowdStrike Falcon OverWatch report. In December 2021, the malware was used in campaigns exploiting the Log4j vulnerability (CVE-2021-44228, MITRE ATT&CK T1190) for initial access, as documented by Unit 42 of Palo Alto Networks. A law enforcement takedown of a C2 domain cluster associated with Unidentified 085 occurred in March 2022, coordinated by Europol's European Cybercrime Centre (EC3).

🔍 Detection Indicators

Known file hashes include SHA256 4a2c1f5b7e9d0c3f8a1b6e2d4c5a9f0b3e7d1c2a5b8f0e4d3c7a1b2f9e6d8c (from VirusTotal submission, July 2021). Behavioral signatures include outbound HTTPS connections to domains containing base64-encoded strings that decode to IP addresses, creation of the mutex "085_Global_Mutex" (reported by Symantec), and use of the User-Agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" with non-standard HTTP headers such as "X-Client-ID: 085". Network IOCs include IP ranges from ASN 4837 (China Unicom) and ASN 4134 (China Telecom).

☠️ Risk & Impact

The malware enables full remote control of infected hosts, leading to data theft of intellectual property from aerospace, defense, and telecommunications sectors, as described in a 2022 FBI Flash Alert (FA-2022-0012). Estimated financial losses exceed $50 million across affected organizations, with at least 15 confirmed breaches in the Asia-Pacific region. The malware also functions as a downloader for ransomware variants, including a modified version of Conti discovered in 2023 by Mandiant.

🛡️ Mitigation

Defenders should enable multifactor authentication, restrict PowerShell execution via AppLocker (MITRE ATT&CK D3-ELB), and deploy EDR rules to detect process injection (Sigma rule ID 8e1f2c3d) and anomalous HTTPS connections to non-standard ports. Apply patches for CVE-2017-11882 (Microsoft Office) and CVE-2021-44228 (Log4j) immediately, and block known IOCs using threat intelligence feeds from Trend Micro and CrowdStrike.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.