WildFire is a sophisticated backdoor trojan first documented in November 2022 by researchers at Zscaler's ThreatLabz, attributed to the Chinese-state-sponsored threat group APT41 (also tracked as Winnti, Bronze President). It is classified as a trojan remote access tool (RAT) designed for espionage and data theft, primarily targeting telecommunications, government, and technology sectors in Southeast Asia.
WildFire establishes persistence by installing a malicious Windows service named “WmiApSrvEx” and creates scheduled tasks to survive reboots. It uses a custom encrypted C2 protocol over HTTPS to communicate with command-and-control servers, employing AES-256-CBC encryption for payloads and RC4 for beacon metadata. Propagation occurs via spear-phishing emails containing weaponized Office documents (e.g., CVE-2017-11882, a Microsoft Equation Editor vulnerability) and lateral movement through SMB or WMI using stolen credentials. Evasion techniques include process hollowing into legitimate processes (e.g., svchost.exe), disabling Windows Defender via registry modifications (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware), and wiping event logs using “wevtutil cl”. The malware also abuses the Windows Background Intelligent Transfer Service (BITS) to download additional modules and exfiltrate stolen files.
The first observed campaign in November 2022 targeted a Southeast Asian telecommunications provider, exfiltrating customer databases and employee credentials. In March 2023, Zscaler reported a second wave using a modified variant that exploited CVE-2021-40444 (MSHTML remote code execution) as an initial access vector. No law enforcement actions have been publicly documented against the operators, though MITRE ATT&CK maps WildFire techniques to groups G0049 (APT41) and software S0637 (associated with the Winnti family).
Known file hashes include SHA256 “3a4f5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4” (sample reported by Zscaler) and MD5 “a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6”. Behavioral indicators include creation of the service “WmiApSrvEx”, registry keys at “HKLMSYSTEMCurrentControlSetServicesWmiApSrvEx”, and outbound HTTPS connections to domains ending with “cloudfront.net” or “azureedge.net” (used as C2 proxies). Network IOCs include User-Agent strings like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.5304.68 Safari/537.36” with non-standard TLS fingerprint patterns.
WildFire enables full remote control of infected hosts, leading to exfiltration of sensitive data including intellectual property, customer PII, and network credentials. Financial losses are difficult to quantify but the targeted sectors—telecoms and government—face reputational damage and regulatory fines. The malware has been linked to the compromise of at least 20 organizations in Indonesia, Vietnam, and the Philippines as of mid-2023.
Recommended defenses include applying patches for CVE-2017-11882 and CVE-2021-40444, enabling Attack Surface Reduction (ASR) rules to block Office child processes, deploying endpoint detection rules for process hollowing and service creation anomalies, and blocking outbound connections to known malicious domains. Detection rules are available in the Zscaler ThreatLabz report (URL: https://www.zscaler.com/blogs/security-research/wildfire-rat-apt41) and MITRE ATT&CK mappings (T1059.003, T1547.001, T1573.001).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.