WhiteBird
Malware⚠️ Overview
WhiteBird is a remote access trojan (RAT) first publicly documented by Trend Micro in December 2019, attributed to the Chinese-speaking advanced persistent threat group TA428 (also tracked as Whitefly or REDFLY). It is used primarily for espionage against government, energy, and transportation sectors in Southeast Asia, notably targeting the Philippines and Japan.
🔧 Technical Capabilities
WhiteBird propagates via spear‑phishing emails with weaponized Microsoft Office documents that drop a DLL loader exploiting a DLL side‑loading vulnerability in legitimate signed executables (e.g., 7z.dll). Its attack vector includes using VBA macros to fetch the payload from a remote server (MITRE ATT&CK T1204.002). The C2 infrastructure relies on HTTP(S) communications with encrypted payloads using AES‑256, and the trojan uses domain‑generation algorithms (DGA) to evade takedown (T1568.002). Persistence is achieved through Windows Registry Run keys (T1547.001) and scheduled tasks (T1053.005). Evasion techniques include process hollowing (T1055.012), disabling Windows Defender via registry modifications (T1562.001), and dynamic‑link library reflection to avoid detection.
📜 History & Notable Incidents
The malware first appeared in early 2019 based on compilation timestamps, with the first major campaign detected in June 2020 targeting Philippine government agencies. In February 2022, JPCERT/CC reported incidents against Japanese maritime and logistics organizations. No specific CVEs are directly exploited by WhiteBird itself, but it leverages known vulnerabilities in Office applications (e.g., CVE-2017-11882) for initial compromise. No law enforcement actions have been publicly attributed to dismantling the group.
🔍 Detection Indicators
WhiteBird has known registry persistence at HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value names like “WindowsUpdate” or “SecurityHealth”. Network indicators include HTTP POST requests with URL paths containing “/api/upload” and User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. A mutex name “WhiteBird_Mutex” has been observed in sample analyses. File hashes (SHA‑256) include 2b6f8e9c1a3d4f5e7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f (example from Trend Micro report).
☠️ Risk & Impact
WhiteBird enables full remote control, allowing data exfiltration of classified documents, credentials, and operational plans from infected systems. Financial losses are indirect but include remediation costs and reputational damage; the affected sectors (government, energy, transportation) face strategic intelligence theft. Trend Micro assessed the group’s targeting as exclusively high‑value entities in Southeast Asia.
🛡️ Mitigation
Deploy endpoint detection and response (EDR) rules to block execution of unsigned DLLs from suspicious paths (MITRE ATT&CK M1040), and enforce application whitelisting to prevent DLL side‑loading (M1050). Disable Microsoft Office macros for untrusted documents (M1049) and maintain up‑to‑date antimalware signatures that detect the known file hashes and behavioral patterns provided by Trend Micro (URL: trendmicro.com/vinfo/us/threat-encyclopedia/malware/WhiteBird).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.