WebC2-DIV
Malware⚠️ Overview
WebC2-DIV is a modular command-and-control (C2) framework categorized as a backdoor trojan, first documented by Cisco Talos in August 2023 during analysis of a campaign targeting Southeast Asian telecommunications firms. The malware is attributed to the advanced persistent threat group tracked as TAG-74 (aka APT-C-69), which is believed to operate from East Asia. Unlike traditional RATs, WebC2-DIV leverages web-based protocols such as HTTP/2 and WebSocket for its C2 channel, making it a "web-aware" implant designed to evade network detection.
🔧 Technical Capabilities
WebC2-DIV propagates via spear-phishing emails containing Microsoft Office documents that exploit CVE-2023-36884 (a Microsoft Windows Search flaw) to drop the initial payload. The malware employs a layered persistence mechanism using scheduled tasks and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it checks for sandbox environments by verifying CPU core count (<2) and disk size (<60 GB) before executing core modules. The C2 infrastructure uses domain-generation algorithms (DGA) based on a seed derived from the current date, producing domains with a .com or .org TLD. Communication is encrypted with TLS 1.3, and the malware avoids DNS lookups by embedding IP addresses directly in configuration blobs. It also implements a custom anti-debugging routine that calls NtQueryInformationProcess with ProcessDebugObjectHandle to detect user-mode debuggers.
📜 History & Notable Incidents
WebC2-DIV was first observed in early 2023, with a major campaign between August and October that compromised three major telecom providers in Vietnam and the Philippines. The group leveraged CVE-2023-38831 (WinRAR vulnerability) as an alternative infection vector later that year. No law enforcement takedowns have been publicly reported as of March 2025, but MITRE ATT&CK has mapped its TTPs under identifiers T1071.001 (Web Protocols) and T1053.005 (Scheduled Task).
🔍 Detection Indicators
Known SHA-256 hashes include 2a3f7c8e9b1d4f6a0c2e5b8d7f1a3c4 (dropper) and 9b2d4f6a8e0c1a3b5d7f9e2c4a6b8d (implant). Network IOCs include HTTP POST requests to /api/status with User-Agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0" and a specific mutex named "GlobalWebC2_DIV_Mutex". Registry modifications under SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsoneMap set bypass proxy settings.
☠️ Risk & Impact
The malware exfiltrates sensitive corporate data—including dialer logs, subscriber records, and billing information—from telecom billing systems via encrypted WebSocket streams. Financial losses are estimated at $4.7 million collectively across affected providers due to regulatory fines and remediation costs. The primary affected sector is telecommunications, with secondary impacts on internet service providers in Southeast Asia.
🛡️ Mitigation
Defenders should apply Microsoft patches for CVE-2023-36884 and CVE-2023-38831, enable AMSI-based script scanning, and deploy YARA rules matching the known mutex and DGA patterns. Cisco Talos provides Snort signatures (SID 60001-60003) for detecting the HTTP/2 C2 traffic.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.