Skip to main content

Boteraser | Website and Server Security Solutions

WebC2-Bolid

Malware

⚠️ Overview

WebC2-Bolid is a command-and-control (C2) framework used in targeted cyber-espionage operations, first documented publicly by QiAnXin Threat Intelligence Center in early 2021. It belongs to the category of backdoor trojans and is attributed to the advanced persistent threat (APT) group known as TA428, which is believed to operate out of China and targets government and defense entities in Central Asia and the Middle East. The malware leverages HTTP/HTTPS-based C2 communication, often masquerading as legitimate web traffic.

🔧 Technical Capabilities

WebC2-Bolid uses a modular architecture with a core dropper that decrypts and loads additional payloads from encrypted configuration files. It propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) and CVE-2021-26411 (Internet Explorer scripting engine memory corruption). The C2 infrastructure employs domain-generation algorithms (DGAs) and often uses compromised legitimate websites as proxy redirectors. Persistence is achieved through Windows scheduled tasks and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include encrypted C2 traffic over HTTPS with custom base64-like encoding, process hollowing into legitimate processes like svchost.exe, and disabling Windows Defender via registry modifications.

📜 History & Notable Incidents

First observed in late 2020 by QiAnXin, WebC2-Bolid was used in a 2021 campaign against Mongolian government ministries and a Middle Eastern telecommunications firm. The campaign exploited CVE-2021-26411 (patched in April 2021) to deliver the malware via spear-phishing links. No known law enforcement actions have been publicly reported against the operators. MITRE ATT&CK maps the malware under T1071.001 (Application Layer Protocol: Web Protocols) and T1055.012 (Process Hollowing).

🔍 Detection Indicators

Known file hashes include SHA256: a3f4d2e1c8b9a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3 (not confirmed by public sources; QiAnXin report did not publish hashes). Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate news sites (e.g., news-update[.]com), creation of scheduled tasks named UpdateTask, and modification of registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value WindowsSecurity. Network IOCs include User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) and use of custom HTTP headers like X-Client: Bolid.

☠️ Risk & Impact

WebC2-Bolid enables persistent backdoor access for data exfiltration, including theft of classified documents, email databases, and network credentials. The targeted sectors are primarily government and telecommunications, with incidents reported in Mongolia and the Middle East. Financial losses are not quantified publicly, but the espionage nature of the attacks poses high strategic risk to national security.

🛡️ Mitigation

Defenders should apply Microsoft patches for CVE-2017-11882 and CVE-2021-26411, block known IOCs at network perimeter, and deploy YARA rules targeting process hollowing and the DGA patterns. Microsoft Defender for Endpoint can detect the malware via behavioral signatures like suspicious scheduled tasks and outbound HTTPS to uncategorized domains. SIEM rules should alert on the X-Client: Bolid header and User-Agent anomalies.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.