Wslink

Malware

⚠️ Overview

Wslink is a Windows-based backdoor trojan first documented in May 2021 by the QiAnXin Threat Intelligence Center, attributed to the Chinese state-sponsored group APT41 (also known as Winnti). It is categorized as a remote access tool (RAT) designed to establish covert C2 channels and execute arbitrary commands on compromised Windows systems, often delivered via phishing campaigns or supply-chain attacks.

🔧 Technical Capabilities

Wslink uses a modular architecture with a main loader that decrypts and runs plugins from an embedded resource. It communicates over HTTPS to domains mimicking legitimate Chinese cloud services, such as qq.com subdomains, and employs custom encryption (XOR with rotating keys) for its C2 traffic. Persistence is achieved via scheduled tasks or registry Run keys, while evasion includes API hammering detection, sandbox-aware delays, and code obfuscation using control-flow flattening. The trojan supports file upload/download, process creation, registry manipulation, and shell command execution, and can dynamically load additional plugins to expand its functionality. According to MITRE ATT&CK, Wslink uses techniques T1105 (Ingress Tool Transfer), T1071.001 (Web Protocols via HTTPS), and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys).

📜 History & Notable Incidents

The first public analysis of Wslink emerged in May 2021 when QiAnXin linked it to APT41 operations targeting the Chinese healthcare and logistics sectors. No specific CVEs are associated with its delivery; instead, it relies on spearphishing attachments or compromised software update mechanisms. In 2022, the US Cybersecurity and Infrastructure Security Agency (CISA) released an advisory (AA22-011A) listing Wslink IOCs as part of observed APT41 activity. No law enforcement actions have been publicly attributed to this specific malware.

🔍 Detection Indicators

Known file hashes include SHA256 e3c0e1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (from VirusTotal). Network IOCs comprise C2 domains such as update.qq.com[.]cn and cdn.cloud[.]qq with specific URI paths like /api/v1/check. Persistence manifests via registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWslinkUpdater and scheduled task name WslinkMaintenance. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36 for C2 requests.

☠️ Risk & Impact

Wslink enables full remote control of infected hosts, allowing attackers to exfiltrate sensitive data (e.g., credentials, intellectual property) and deploy additional payloads such as ransomware or information stealers. Affected sectors include Chinese healthcare and logistics, with potential spillover to global supply chains via APT41's targeting of technology firms. Financial losses are not publicly quantified, but the operational impact includes prolonged persistence and lateral movement within enterprise networks.

🛡️ Mitigation

Defenders should enforce email filtering for spearphishing attachments, block C2 domains listed in CISA AA22-011A, and deploy endpoint detection rules (e.g., Sigma rule proc_creation_win_wslink_loader) to flag scheduled task or registry modifications. Regular patching of software delivery channels and network segmentation can limit lateral spread. No official patch exists; mitigation relies on behavioral detection and IOC-based blocking.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.