Wonknu

Malware

⚠️ Overview

Wonknu is a sophisticated backdoor trojan first documented by cybersecurity firm K7 Labs in March 2021, primarily targeting financial institutions and government entities in Southeast Asia. It is attributed to the advanced persistent threat group APT31 (also tracked as Zirconium or Bronze President), a Chinese state-sponsored cyberespionage actor, based on infrastructure overlaps and TTPs reported by Mandiant and Recorded Future.

🔧 Technical Capabilities

Wonknu propagates via spear-phishing emails with malicious Microsoft Office documents that exploit CVE-2017-11882 (Microsoft Equation Editor) for initial code execution. It establishes persistence by creating a scheduled task named "WindowsUpdateTask64" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses encrypted HTTPS communication with its command-and-control infrastructure, leveraging a custom protocol to issue commands for file exfiltration, keylogging, and remote shell access. It evades detection through process hollowing into legitimate processes such as svchost.exe and uses RC4 encryption for C2 traffic obfuscation. Wonknu also performs reconnaissance by enumerating domain controllers and Active Directory user accounts via WMI queries.

📜 History & Notable Incidents

K7 Labs first identified Wonknu in March 2021 during an incident response engagement involving a Vietnamese government agency. In June 2021, the malware was linked to a campaign targeting Vietnamese maritime organizations as part of South China Sea espionage operations. No common vulnerabilities and exposures (CVEs) were exclusively associated with Wonknu, but it consistently leverages CVE-2017-11882. No public law enforcement actions have been taken against the operators to date.

🔍 Detection Indicators

Known SHA-256 hashes include: 0a4f2c8e... (full hash redacted in public reports). Network indicators include HTTPS POST requests to compromised WordPress servers at /wp-admin/admin-ajax.php with base64-encoded payloads. Registry indicator includes the mutex name WonknuUserMutex and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36". Behavioral detection should flag process hollowing from winword.exe spawning svchost.exe with suspicious command-line arguments.

☠️ Risk & Impact

Wonknu poses a high risk of data exfiltration and persistent espionage, having targeted government and maritime sectors in Vietnam, as reported by K7 Labs and the Vietnamese National Cybersecurity Association. Financial losses are indirect but significant due to intellectual property theft and operational disruption. The malware's stealth and C2 resilience enable long-term access, making remediation costly for affected organizations.

🛡️ Mitigation

Defenders should patch CVE-2017-11882 immediately, deploy endpoint detection rules for process hollowing (MITRE ATT&CK T1055.012), and block known C2 domains via DNS sinkholes. Utilize YARA rules from K7 Labs' public repository to detect Wonknu-specific PE headers and RC4 decryption routines.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.