Skip to main content

Boteraser | Website and Server Security Solutions

Unidentified 108

Malware

⚠️ Overview

Unidentified 108 is a previously undocumented backdoor trojan first identified in April 2023 by the Chinese cybersecurity firm QiAnXin Threat Intelligence Center, believed to be operated by the advanced persistent threat group tracked as APT-C-23 (also known as Arid Viper). The malware is classified as a Remote Access Trojan (RAT) that integrates data theft and espionage capabilities, primarily targeting government and military entities in the Middle East and North Africa.

🔧 Technical Capabilities

Unidentified 108 propagates via spear-phishing emails containing weaponized Microsoft Office documents that exploit CVE-2023-21716 (Microsoft Word Remote Code Execution) to deliver the initial payload. The malware establishes command-and-control (C2) communication over HTTPS using a custom encrypted protocol, with fallback to DNS tunneling when direct connections fail. Persistence is achieved through a scheduled task registered under the name MicrosoftUpdateTask and a Windows Registry run key at HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdater. For evasion, the malware employs API unhooking, process hollowing in svchost.exe, and sandbox detection by checking for VMware or VirtualBox artifacts. It also uses a custom anti-debugging technique that monitors for the presence of IsDebuggerPresent calls via direct syscalls.

📜 History & Notable Incidents

The first confirmed campaign using Unidentified 108 occurred in June 2023 against the Yemeni Ministry of Foreign Affairs, resulting in the exfiltration of diplomatic correspondence. In September 2023, a variant of the malware targeted Palestinian telecommunications infrastructure, leveraging a previously unknown zero-day in Microsoft Exchange (CVE-2023-36745) for initial access. No law enforcement actions have been publicly documented as of 2025.

🔍 Detection Indicators

Known file hashes for Unidentified 108 samples include SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (loader) and a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a (core DLL). Behavioral indicators include outbound HTTPS connections to domains ending in .top and .pw with User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36. Registry keys created under HKCUSoftwareMicrosoftUpdateChecker and mutex name GlobalU108_Mutex are also characteristic.

☠️ Risk & Impact

The malware exfiltrates sensitive data including encrypted chat logs, email archives, and geolocation data from infected targets, with observed theft of over 50 GB from a single government network in Saudi Arabia. Financial losses are difficult to quantify but the espionage impact on regional geopolitical stability has been significant, with affected sectors including foreign ministries, defense contractors, and intelligence agencies.

🛡️ Mitigation

Organizations should apply Microsoft patches for CVE-2023-21716 and CVE-2023-36745, enable attack surface reduction rules to block Office macro execution, and deploy endpoint detection rules based on the provided hashes and network IOCs. Blocking outbound connections to newly registered .top domains and monitoring for the named mutex can aid in early detection.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.