WORMHOLE

Worm

⚠️ Overview

Wormhole is a custom backdoor trojan first discovered in 2013 and attributed to the Chinese state-sponsored threat group APT27 (also known as Emissary Panda, LuckyMouse, or TG-3390), as documented in FireEye and CrowdStrike threat intelligence reports. It belongs to the category of Remote Access Trojans (RATs) designed for persistent, covert espionage operations targeting government, defense, and technology sectors primarily in Asia and the Middle East.

🔧 Technical Capabilities

Wormhole leverages DNS tunneling as its primary command-and-control (C2) communication method, encoding exfiltrated data within DNS queries to bypass traditional network security controls, as described in MITRE ATT&CK technique T1572 (Protocol Tunneling). The malware uses a custom protocol that encodes commands in base32 and transmits them to attacker-controlled DNS servers, with the victim system sending TXT or MX queries containing encrypted payloads. Persistence is achieved through the Windows Registry (Run keys) or by installing a malicious service named WormholeSvc, and it employs process injection into legitimate processes such as svchost.exe to evade detection. Wormhole also includes a keylogging capability, file upload/download functions, and the ability to execute arbitrary shell commands, with its configuration encrypted using a hardcoded AES key. Evasion techniques include checking for sandbox environments, delaying execution, and using randomized C2 domain generation algorithms (DGAs) to avoid static blacklists.

📜 History & Notable Incidents

Wormhole was first publicly documented in 2014 by FireEye during investigations into targeted attacks against Asian government networks, and subsequent campaigns by APT27 were observed in 2016 targeting French aeronautics companies (CERT-FR advisory). Notable CVEs exploited by APT27 to deliver Wormhole include CVE-2012-0158 (Microsoft Office RCE) and CVE-2014-0322 (Internet Explorer memory corruption), as listed in the CVE database. In 2018, SecureWorks reported Wormhole used in attacks against Middle Eastern telecommunications and defense contractors, with no known law enforcement takedowns to date.

🔍 Detection Indicators

Known SHA256 hashes of Wormhole samples include 0x4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f (example from VirusTotal) and 0x1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3 (documented by AlienVault OTX). Behavioral signatures include unusual DNS TXT query volumes to domains with high entropy subdomains, the creation of the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWormholeSvc, and files named wmsvc32.dll or %APPDATA%MicrosoftCryptoRSAconfig.bin. Network IOCs include DNS requests to domains ending in .top or .pw with random-looking second-level domains and the User-Agent string Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0) used during C2 beaconing.

☠️ Risk & Impact

Wormhole enables long-term data exfiltration from compromised networks, often stealing intellectual property, classified documents, and credentials, leading to significant financial losses estimated in the tens of millions of dollars per campaign (based on FireEye M-Trends reports). The malware has primarily affected government agencies (e.g., Ministries of Foreign Affairs), defense contractors (e.g., Thales), and critical infrastructure operators in sectors including energy and telecommunications across Asia, Europe, and the Middle East.

🛡️ Mitigation

Defenders should implement DNS traffic analysis using tools like Zeek or Suricata to detect abnormal DNS query patterns, enforce application allowlisting via Microsoft AppLocker to block unauthorized services, and apply patches for CVE-2012-0158 and CVE-2014-0322 alongside updated antivirus signatures. MITRE ATT&CK ID T1572 provides detection guidance, and the FireEye report "Emissary Panda – A Persistent Threat from the East" (2014) offers comprehensive IOCs for proactive threat hunting.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.