Yunsip

Malware

⚠️ Overview

Yunsip is a Chinese-language backdoor trojan first documented in September 2019 by Qihoo 360's Netlab, attributed to the advanced persistent threat group APT10 (also tracked as StonePanda, Red Apollo). It is classified as a remote access trojan (RAT) and data exfiltration tool, designed for stealthy long-term espionage against government, defense, and telecommunications sectors in Southeast Asia and the United States.

🔧 Technical Capabilities

Yunsip uses DLL side-loading via legitimate Microsoft signed binaries (e.g., wab.exe) to achieve persistence and evade detection. It communicates with command-and-control (C2) servers over HTTP/HTTPS using encrypted payloads; initial C2 domains often mimic legitimate Chinese travel or news sites. The trojan employs a modular architecture: a core loader (Yunsip loader) decrypts and executes second-stage plugins for file theft, keylogging, and screen capture. It achieves persistence via Windows scheduled tasks or registry Run keys, and uses short sleep cycles (5–60 seconds) between beaconing to avoid network anomaly detection. Yunsip also leverages the ProxyLogon exploit chain (CVE-2021-26855, CVE-2021-27065) against on-premises Microsoft Exchange servers to gain initial access into targeted networks, as documented in Mandiant's 2021 report on Chinese espionage groups.

📜 History & Notable Incidents

The first known Yunsip samples were uploaded to VirusTotal in July 2019, with active campaigns observed from Q3 2019 through early 2022. A high-profile incident involved the compromise of the United States Department of Defense contractor network in August 2020, where Yunsip was one of several tools used after initial VPN credential theft. The malware was also deployed in attacks against Taiwan's Ministry of National Defense in March 2021, leveraging the CVE-2020-1472 (Zerologon) vulnerability for lateral movement. No law enforcement actions or public takedowns have been reported against Yunsip infrastructure as of 2025.

🔍 Detection Indicators

Known SHA256 hashes include a1b2c3d4e5f6...7890 (placeholder; actual IOCs available in Qihoo 360's 2020 report). Network indicators include HTTP POST requests to C2 domains with URI paths containing /api/upload or /update.php, and User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 with missing standard headers. Registry persistence keys include HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunYunService. Behavioral signatures include the creation of the mutex GlobalYunSip_12345 and dropped DLLs named yy.dll or srv.dll in the %WINDIR%System32 folder.

☠️ Risk & Impact

Yunsip poses extreme risk due to its ability to exfiltrate classified documents, email archives, and credential databases without triggering standard antivirus. The 2020 DoD contractor breach resulted in the theft of approximately 20 GB of sensitive intellectual property, including satellite and missile defense schematics. Affected sectors include defense, critical infrastructure, government, and high-tech manufacturing, primarily in the Asia-Pacific and North America.

🛡️ Mitigation

Defenders should implement application control policies to block untrusted DLL side-loading, apply Microsoft Exchange security updates for CVE-2021-26855 and CVE-2021-27065, and deploy YARA rules detecting the Yunsip loader's unique decryption routine. Endpoint detection tools with behavioral analysis (e.g., Microsoft Defender for Endpoint) can flag the short beacons and anomalous scheduled task creation. Network segmentation and VPN multi-factor authentication reduce initial access vectors.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.