Unidentified 100 (APT-Q-12)

Malware

⚠️ Overview

Unidentified 100 (APT-Q-12) is a Chinese-language advanced persistent threat (APT) group first publicly documented by the Qi-Anxin Threat Intelligence Center (QAX-TIC) in 2022. It is categorized as a cyberespionage group, primarily targeting government entities, defense contractors, and high-tech organizations in Southeast Asia and Central Asia. The group is believed to operate on behalf of the Chinese state and has been active since at least 2020.

🔧 Technical Capabilities

The group leverages custom malware payloads delivered through spear-phishing emails with malicious Office documents exploiting CVE-2017-11882 (Microsoft Office Equation Editor vulnerability). Post-compromise, the attackers deploy a modular backdoor named QuasarRAT variant that communicates over HTTPS to a command-and-control (C2) infrastructure hosted on compromised legitimate websites and cloud services. Persistence is achieved via scheduled tasks and registry Run keys. Evasion techniques include code obfuscation via custom packers, process injection into svchost.exe, and use of legitimate LOLBins (e.g., PowerShell, Certutil) for file downloads. The group also employs pass-the-hash and lateral movement over SMB using stolen domain credentials.

📜 History & Notable Incidents

In early 2023, QAX-TIC linked APT-Q-12 to a campaign targeting a Southeast Asian government ministry, deploying a custom info-stealer that exfiltrated classified documents via encrypted Telegram channels. No CVEs have been directly attributed to this group, but they frequently exploit known vulnerabilities like CVE-2018-0798 (Microsoft Office Excel XSS). No law enforcement actions have been reported.

🔍 Detection Indicators

Network indicators include C2 domain patterns such as *.oss-cn-hongkong[.]aliyuncs[.]com (Alibaba Cloud) and User-Agent strings containing “Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0)”. File hashes are not publicly available, but behavioral indicators include calls to obfuscated PowerShell commands and creation of scheduled tasks named “OneDriveUpdatecheck” in the user’s task folder.

☠️ Risk & Impact

Damage primarily involves long-term espionage: theft of intellectual property, military plans, and diplomatic communications. Affected sectors include government, defense, and telecommunications. Financial losses are indirect but could exceed hundreds of millions due to compromised national security.

🛡️ Mitigation

Defenders should enforce application whitelisting for Office processes, block outbound connections to rarely used cloud regions (e.g., Hong Kong), and deploy YARA rules for custom QuasarRAT variants. Microsoft provide detection signatures as part of their Defender ATP Advanced Threat Hunting. Refer to Qi-Anxin’s 2022 threat report for detailed IOCs.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.