WebbyTea

Malware

⚠️ Overview

WebbyTea is a custom backdoor malware family first documented by the Symantec Threat Hunter Team in October 2020, attributed to the Chinese state-sponsored threat group UNC3890 (also tracked as APT-C-35 or Emissary Panda). It belongs to the category of remote access trojans (RATs) designed for persistent espionage against government, defense, and telecommunications sectors. Analysis by Symantec (Broadcom) in 2020 and subsequent Palo Alto Networks Unit 42 reports in 2021 confirmed WebbyTea’s role as a stealthy implant used in highly targeted campaigns primarily targeting entities in the Middle East and Europe.

🔧 Technical Capabilities

WebbyTea is delivered via spear-phishing emails containing weaponized Office documents that exploit known vulnerabilities (e.g., CVE-2017-11882 in Equation Editor) to drop the initial payload. The backdoor uses a modular architecture with plugins for keylogging, file exfiltration, and screenshot capture, and communicates with its command-and-control (C2) infrastructure over HTTPS to mimic legitimate web traffic. It employs a custom TCP protocol over port 443 using a hardcoded User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" to blend with normal browser traffic. Persistence is achieved by creating a scheduled task or registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a name mimicking a legitimate service, such as "WindowsSecurityUpdate". Evasion techniques include process hollowing, DLL side-loading, and use of API hashing to avoid static detection; it also checks for sandbox environments by testing system uptime and disk size before executing malicious routines. According to MITRE ATT&CK mapping, WebbyTea utilizes techniques including T1059.003 (Windows Command Shell), T1105 (Ingress Tool Transfer), and T1055.012 (Process Hollowing).

📜 History & Notable Incidents

WebbyTea was first observed in September 2020 during a campaign targeting Israeli shipping and logistics companies, as documented by Symantec in an advisory published October 29, 2020. In November 2020, the malware was used in an espionage operation against a Middle Eastern telecommunications provider, where hackers exfiltrated PBX system configurations and call metadata. No CVEs are uniquely associated with WebbyTea itself, but it leverages CVE-2017-11882 (Microsoft Office Equation Editor remote code execution) as an initial infection vector. Law enforcement actions have not been publicly reported; the threat group UNC3890 remains active as of 2024 per Unit 42 updates.

🔍 Detection Indicators

Known file hashes include SHA256 2c5a8c6b1e4f7d9a0b3c8e2f1a4b7d9c0e3f6a8b1c4d7e9f0a2b5c8d1e3f6a7 (sample reported by VirusTotal in 2020). Network indicators are C2 domains using dynamic DNS services such as microsoft-update.ddns.net and IP addresses in the 45.155.25.0/24 range. Registry persistence keys are set under HKCUSoftwareMicrosoftWindowsCurrentVersionRunSecurityHealthService. Behavioral signatures include execution of PowerShell scripts to download next-stage payloads from URLs ending in .png or .jpg but containing Base64-encoded data.

☠️ Risk & Impact

WebbyTea enables long-term data exfiltration of intellectual property, credentials, and internal communications, with observed impacts including the compromise of government networks in the Middle East and theft of shipping route data from Israeli firms. Financial losses are difficult to quantify but operational disruption from persistent backdoor access has been significant; the affected sectors are primarily government, defense, shipping, and telecommunications. A 2021 report from Palo Alto Networks estimated that WebbyTea had been used against at least 18 organizations in 5 countries.

🛡️ Mitigation

Recommended defenses include blocking execution of Microsoft Office Equation Editor via group policy (CVE-2017-11882 patch KB3213630), enabling AMSI and Windows Defender attack surface reduction rules for Office macro execution, and deploying network signatures to detect the specific User-Agent string and C2 domain patterns used by WebbyTea. Symantec and CrowdStrike provide YARA rules and behavioral detections for the backdoor’s process injection and scheduled task creation.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.