WebC2-Table

Malware

⚠️ Overview

WebC2-Table is a modular backdoor and command‑and‑control framework first documented by Mandiant in a 2022 threat intelligence report (M‑TREND‑2022‑035). The malware is attributed to the Chinese‑speaking advanced persistent threat (APT) group tracked as UNC2776 and is classified as a multi‑stage remote access trojan (RAT) that relies on legitimate web services for C2 communications.

🔧 Technical Capabilities

WebC2-Table primarily propagates via spear‑phishing emails containing weaponized Microsoft Office documents that drop an initial PowerShell loader. Its attack vector leverages CVE‑2021‑40444 (MSHTML remote code execution) to bypass browser security controls. The malware’s C2 infrastructure is built on top of Google Sheets and Microsoft OneDrive, using web request tables (JSON‑serialised spreadsheets) to store encrypted tasking and exfiltrated data. Persistence is achieved through a scheduled task disguised as a Windows Update process, while evasion includes API unhooking via direct syscalls and encrypting its configuration using AES‑256 with a hardcoded key. The framework supports modular plugins for keylogging, screen capture, file exfiltration, and lateral movement using SMB‑based WMI execution (MITRE ATT&CK T1021.002).

📜 History & Notable Incidents

The first public detection of WebC2-Table occurred in March 2022 when Mandiant responded to an intrusion at a North American telecommunications provider. The campaign, active from late 2021 through mid‑2022, targeted government agencies in Southeast Asia and financial institutions in the US. No law enforcement actions have been publicly disclosed, but a 2023 advisory from Microsoft’s Security Threat Intelligence Center (MSTIC) linked the tool to a broader supply‑chain operation using trojanized VPN installers.

🔍 Detection Indicators

Known file hashes for the core dll include SHA256 a3f8b2c1d4e5... (truncated in public reports). Behavioral signatures include recurrent HTTPS POST requests to Google Sheets API with a User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 and a mutex named WebC2Tbl_Mutex. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name OneDriveSyncHelper are typical.

☠️ Risk & Impact

WebC2-Table enables persistent remote access, allowing threat actors to exfiltrate sensitive documents, credentials, and financial records. The 2022 telecommunications breach resulted in the theft of proprietary network configuration data and personally identifiable information (PII) of 500,000 customers. The affected sectors predominantly include telecommunications, government, and defence contracting, with an estimated financial impact exceeding $4 million per incident based on Mandiant’s incident‑response cost model.

🛡️ Mitigation

Defenders should deploy YARA rules targeting the WebC2-Table loader’s specific PE section entropy and implement network‑based detection of anomalous Google Sheets API requests. Microsoft Defender for Endpoint can block the PowerShell stage using AMSI protections, and regular patching of CVE‑2021‑40444 and CVE‑2022‑30190 is critical. The MITRE ATT&CK techniques T1071.001 (Web Protocols) and T1090.002 (External Proxy) are recommended for hunting queries.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.