[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Jen Miller-Osborn](https://unit42.paloaltonetworks.com/author/jen-miller-osborn/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 4, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Skype](https://unit42.paloaltonetworks.com/tag/skype/)
  * [T5000](https://unit42.paloaltonetworks.com/tag/t5000/)
  * [T9000](https://unit42.paloaltonetworks.com/tag/t9000/)
  * [Trojans](https://unit42.paloaltonetworks.com/tag/trojans/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/t9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques/?pdf=download&lg=en&_wpnonce=0e33cfdd78 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/t9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques/?pdf=print&lg=en&_wpnonce=0e33cfdd78 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=T9000:%20Advanced%20Modular%20Backdoor%20Uses%20Complex%20Anti-Analysis%20Techniques&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ft9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Ft9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ft9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques%2F&title=T9000:%20Advanced%20Modular%20Backdoor%20Uses%20Complex%20Anti-Analysis%20Techniques "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ft9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques%2F&text=T9000:%20Advanced%20Modular%20Backdoor%20Uses%20Complex%20Anti-Analysis%20Techniques "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ft9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=T9000:%20Advanced%20Modular%20Backdoor%20Uses%20Complex%20Anti-Analysis%20Techniques%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ft9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques%2F "Share in Mastodon")
  Most custom backdoors used by advanced attackers have limited functionality. They evade detection by keeping their code simple and flying under the radar. But during a recent investigation we found a backdoor that takes a very different approach. We refer to this backdoor as T9000, which is a newer variant of the T5000 malware family, also known as Plat1.

In addition to the basic functionality all backdoors provide, T9000 allows the attacker to capture encrypted data, take screenshots of specific applications and specifically target Skype users. The malware goes to great lengths to identify a total of 24 potential security products that may be running on a system and customizes its installation mechanism to specifically evade those that are installed. It uses a multi-stage installation process with specific checks at each point to identify if it is undergoing analysis by a security researcher.

The primary functionality of this tool is to gather information about the victim. In fact, the author chose to store critical files dropped by the Trojan in a directory named "Intel." T9000 is pre-configured to automatically capture data about the infected system and steal files of specific types stored on removable media.

We have observed T9000 used in multiple targeted attacks against organizations based in the United States. However, the malware's functionality indicates that the tool is intended for use against a broad range of users. In this report, we share an analysis of each stage in T9000's execution flow. Stay tuned for a future report in which we will provide more detail on how this tool has been used and the infrastructure we have identified as part of our analysis.

### T9000 Backdoor Analysis

The entire execution flow of the malware is represented in the following diagram:

[![T9000 1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-1-500x244.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-1.png)

As this malware uses a multistage execution flow, we'll discuss each stage individually.

#### Initial Exploitation

The sample of T9000 used in this analysis was originally dropped via a RTF file that contained exploits for both [CVE-2012-1856](https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1856) and [CVE-2015-1641](https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1641). When triggered, an initial shellcode stage is run, which is responsible for locating and executing a secondary shellcode stub. The second stage shellcode reads the initial RTF document and seeks to the end of the file, using the last four bytes as the size of the embedded payload.

With the payload size confirmed, the shellcode will create a file in the %TEMP% folder using a temporary filename. The shellcode will decrypt and subsequently load the embedded payload in the RTF file. The decrypted payload is written to the temporary file and executed using WinExec. The shellcode then attempts to decrypt an embedded decoy document with the same algorithm used to decrypt the payload, which it will save to %TEMP%\\~tmp.doc path. This file is opened using the following command:

*cmd /C %TEMP%\\~tmp.doc*

However, this particular sample did not contain a decoy document.

#### Stage 1

When this temporary file is initially executed, it will begin by creating the following mutex to ensure only one instance of the malware is running at a given time:

*820C90CxxA1B084495866C6D95B2595xx1C3*

It continues to perform a number of checks for installed security products on the victim machine. The following security platforms are queried by checking entries within the HKLM\\Software\\ registry path:

* Sophos
* INCAInternet
* DoctorWeb
* Baidu
* Comodo
* TrustPortAntivirus
* GData
* AVG
* BitDefender
* VirusChaser
* McAfee
* Panda
* Trend Micro
* Kingsoft
* Norton
* Micropoint
* Filseclab
* AhnLab
* JiangMin
* Tencent
* Avira
* Kaspersky
* Rising
* 360

These security products are represented by a value that is binary AND-ed with any other products found. The following numbers represent each respective security product.

*0x08000000 : Sophos* *0x02000000 : INCAInternet* *0x04000000 : DoctorWeb* *0x00200000 : Baidu* *0x00100000 : Comodo* *0x00080000 : TrustPortAntivirus* *0x00040000 : GData* *0x00020000 : AVG* *0x00010000 : BitDefender* *0x00008000 : VirusChaser* *0x00002000 : McAfee* *0x00001000 : Panda* *0x00000800 : Trend Micro* *0x00000400 : Kingsoft* *0x00000200 : Norton* *0x00000100 : Micropoint* *0x00000080 : Filseclab* *0x00000040 : AhnLab* *0x00000020 : JiangMin* *0x00000010 : Tencent* *0x00000004 : Avira* *0x00000008 : Kaspersky* *0x00000002 : Rising* *0x00000001 : 360*

So, for example, if both Trend Micro and Sophos were discovered on a victim machine, the resulting value would be 0x08000800. This numerical value is written to the following file:

*%APPDATA%\\Intel\\avinfo*

The malware proceeds to drop the following files to the %APPDATA%\\Intel directory:

[![T9000 2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-2-500x540.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-2.png)

Additionally, the following two files are written to the Data directory:

[![T9000 3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-3-500x110.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-3.png)

The following table provides a description of each file dropped:

|---------------|----------------------------------------------------------------------|
| **File Name** | **Description**                                                      |
| ~1           | Debug information about files used by malware.                       |
| avinfo        | Installed security products on victim.                               |
| hccutils.dll  | Malicious DLL. Loads ResN32.dll.                                     |
| hccutils.inf  | Malicious INF file. Points to hccutils.dll.                          |
| hjwe.dat      | Encrypted core of malware family.                                    |
| igfxtray.exe  | Legitimate Microsoft executable. Loads hccutils.dll.                 |
| qhnj.dat      | Encrypted plugin. Hooks a number of functions and logs results.      |
| QQMgr.dll     | Malicious DLL. Sets persistence via Run registry key.                |
| QQMgr.inf     | Malicious INF file. Points to QQMgr.dll                              |
| ResN32.dat    | String pointing to path of encrypted core of malware.                |
| ResN32.dll    | Malicious DLL. Decrypts, decompresses, and loads core malware.       |
| tyeu.dat      | Encrypted plugin. Takes screenshots and collects Skype information.  |
| vnkd.dat      | Encrypted plugin. Finds files on removable drives on victim machine. |
| dtl.dat       | Encrypted configuration information.                                 |
| glp.uin       | Plugin configuration information.                                    |

You'll notice that QQMgr\* files are not listed in the original malware execution flow diagram. In the event the victim is running any of the following operating system versions, as well as either Kingsoft, Filseclab, or Tencent security products, the malware will be installed using an alternative method.

* Windows 2008 R2
* Windows 7
* Windows 2012
* Windows 8

In such a situation, the malware will find and run the built-in Microsoft Windows InfDefaultInstall.exe program, which will install a DLL via an INF file. Should Tencent be installed, the malware will execute the InfDefaultInstall.exe program with an argument of 'QQMgr.inf'. Otherwise, it will use 'hccutils.inf' as an argument.

QQMgr.inf will install the QQMgr.dll, while hccutils.inf will install the hccutils.dll library. QQMgr.dll will set the following registry key:

*HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Eupdate - %APPDATA%\\Intel\\ResN32.dll*

The QQMgr.dll file has the following debug string found within it:

*H:\\WORK\\PROJECT\\InfInstallBypassUAC\\Release\\BypassUAC.pdb*

The hccutils.dll file is described later within this post.

After the malware drops the required files, by default the malware will spawn %APPDATA%\\Intel\\igfxtray.exe in a new process, which begins the second stage of the malware's execution.

#### Stage 2

The igfxtray.exe is a legitimate Microsoft Windows executable that [sideloads](https://attack.mitre.org/wiki/DLL_side-loading) the malicious hccutils.dll DLL file. This DLL has the following debug string embedded within it:

*D:\\WORK\\T9000\\hccutils\_M4\\Release\\hccutils.pdb*

Upon loading this malicious DLL, the malware will initially perform the same queries for security products that were witnessed in stage 1.

Three separate techniques for starting stage 3 are used depending on the properties of the victim.

The first technique is used if the victim meets the following criteria:

* Microsoft Windows 8 / Windows Server 2012 R2
* DoctorWeb security product installed

For this situation, the following registry key is set:

*HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\update - %SYSTEM%\\rundll32.exe %APPDATA\\Intel\\ResN32.dll Run*

This ensures that the ResN32.dll library will be run using the 'Run' exported function whenever the machine is rebooted.

The second technique is used if the victim meets any of the following sets of criteria:

* Microsoft Windows 8 / Windows Server 2012 R2

* Not running Kingsoft, Tencent, or DoctorWeb security products

* Microsoft Windows XP or lower

* No security products installed, or running any of the following:
  
  * Sophos
  * GData
  * TrendMicro
  * AhnLab
  * Kaspersky

In these situations, the following persistence technique is used.

*HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\AppInit\_DLLs - %APPDATA%\\Intel\\ResN32.dll*

*HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\LoadAppInit\_DLLs -- 0x1*

Setting these registry keys both enables the AppInit\_DLL functionality, and ensures that every user mode process that is spawned will load the ResN32.dll library. More information about this can be found [here](<https://msdn.microsoft.com/en-us/library/windows/desktop/dd744762(v=vs.85).aspx>).

The third technique is used in any other situation. When this occurs, the malware will first identify the explorer.exe process identifier. It proceeds to inject the ResN32.dll library into this process.

At this point, the third stage of the malware family is loaded.

#### Stage 3

The third stage begins when the ResN32.dll file begins operating. This file contains the following debug string:

*D:\\WORK\\T9000\\ResN\_M2\\Release\\ResN32.pdb*

The ResN32.dll library begins by spawning a new thread that is responsible for the majority of the capabilities built into this sample. This thread begins by checking the operating system version, and once again runs a query on the various security products installed on the victim machine.

Under certain conditions, the following registry key is set, ensuring persistence across reboots:

*HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\update -- c:\\windows\\system32\\rundll32.exe %APPDATA\\Intel\\ResN32.dll Run*

Following this, a new thread is created that is responsible for deleting previously written files. This thread creates the following mutex:

*Global\\\\deletethread*

It proceeds to attempt to delete the following files in an infinite loop until said files have been deleted:

* %STARTUP%\\hccutils.dll
* %STARTUP%\\hccutil.dll
* %STARTUP%\\igfxtray.exe

The ResN32.dll malware proceeds to read in the ResN32.dat file that was previously written to disk. This file contains a path to the hjwe.dat file, which is subsequently read in.

The data within the hjwe.dat file is decrypted using the RC4 algorithm, and subsequently decompressed using the LZMA algorithm. The following script can be used to decrypt the hjwe.dat file, along with the plugins that will be discussed later.  
import sys, pylzma from base64 import \* from binascii import \* from struct import \* def rc4( data , key ): S = range(256) j = 0 out = \[\] for i in range(256): j = (j + S\[i\] + ord( key\[i % len(key)\] )) % 256 S\[i\] , S\[j\] = S\[j\] , S\[i\] i = j = 0 for char in data: i = ( i + 1 ) % 256 j = ( j + S\[i\] ) % 256 S\[i\] , S\[j\] = S\[j\] , S\[i\] out.append(chr(ord(char) ^ S\[(S\[i\] + S\[j\]) % 256\])) return ''.join(out) f = open(sys.argv\[1\], 'rb') fd = f.read() f.close() bytes\_0\_4, bytes\_4\_8, bytes\_8\_12, bytes\_12\_16 = unpack("\<IIII", fd\[0:16\]) if bytes\_0\_4 == 0xf7e4aa65: length = bytes\_8\_12 if len(fd)-16 != length: print "\[\*\] Possible error reading in length of data." key\_size = 260 key = fd\[16:16+key\_size\] data = fd\[16+key\_size:\] decrypted = rc4(data, key) decompressed = pylzma.decompress\_compat(decrypted) f1 = open(sys.argv\[1\]+".decompressed", 'wb') f1.write(decompressed) f1.close print "\[+\] Wrote %s" % (sys.argv\[1\]+".decompressed")

|----------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 | import sys, pylzma from base64 import \* from binascii import \* from struct import \* def rc4( data , key ): S = range(256) j = 0 out = \[\] for i in range(256): j = (j + S\[i\] + ord( key\[i % len(key)\] )) % 256 S\[i\] , S\[j\] = S\[j\] , S\[i\] i = j = 0 for char in data: i = ( i + 1 ) % 256 j = ( j + S\[i\] ) % 256 S\[i\] , S\[j\] = S\[j\] , S\[i\] out.append(chr(ord(char) ^ S\[(S\[i\] + S\[j\]) % 256\])) return ''.join(out) f = open(sys.argv\[1\], 'rb') fd = f.read() f.close() bytes\_0\_4, bytes\_4\_8, bytes\_8\_12, bytes\_12\_16 = unpack("\<IIII", fd\[0:16\]) if bytes\_0\_4 == 0xf7e4aa65: length = bytes\_8\_12 if len(fd)-16 != length: print "\[\*\] Possible error reading in length of data." key\_size = 260 key = fd\[16:16+key\_size\] data = fd\[16+key\_size:\] decrypted = rc4(data, key) decompressed = pylzma.decompress\_compat(decrypted) f1 = open(sys.argv\[1\]+".decompressed", 'wb') f1.write(decompressed) f1.close print "\[+\] Wrote %s" % (sys.argv\[1\]+".decompressed") |

After this file has been decrypted and decompressed, it is written to a file in the %TEMP% directory with a file prefix of '\_\_\_\_RES'. This file, which contains a Windows DLL, is then loaded into the current process. After the malicious library has been loaded, the previously written temporary file is deleted. This begins the last stage of the malware, which will load the core of the malware family.

#### Stage 4

Once the decrypted and decompressed hjwe.dat file is loaded, it begins by checking its parent process against the following list. If the parent process matches the following blacklist, the malicious DLL will exit without performing any malicious activities.

* winlogon.exe
* csrss.exe
* logonui.exe
* ctfmon.exe
* drwtsn32.exe
* logonui.exe
* explore.exe
* System
* Dbgview.exe
* userinit.exe
* lsass.exe
* wmiprvse.exe
* services.exe
* inetinfo.exe
* avp.exe
* Rtvscan.exe

The malware proceeds to collect the username of the victim, as well as the operating system version. It then compares its parent process against the following list of executables:

* winlogon.exe
* csrss.exe
* logonui.exe
* ctfmon.exe
* drwtsn32.exe
* logonui.exe
* System
* Dwm.exe
* QQPCRTP.exe
* Tasking.exe
* Taskhost.exe
* Taskmgr.exe
* Dbgview.exe
* suerinit.exe
* lsass.exe
* wmiprvse.exe
* services.exe
* inetinfo.exe
* avp.exe
* Rtvscan.exe

Notice the repeated check for the 'logonui.exe', as well as the overlap with the previous parent executable check, which implies sloppiness by the malware author.

After these checks are performed, the following mutex is created.

*Global\\\\{A59CF429-D0DD-4207-88A1-04090680F714}*

The following folders are then created:

* utd\_CE31
* XOLOADER
* Update

The path of these folders is determined by the version of Microsoft Windows running. The following possibilities exist:

* %ALLUSERSPROFILE%\\Documents\\My Document\\
* %PUBLIC%\\Downloads\\Update\\

At this point, the malware will read in the dtl.dat file, which contains configuration data. Data contained with this file starting at offset 0x20 is xor-encrypted using a single-byte key of 0x5F. The following script can be used to extract the IP address and port for the C2 server from this file.  
from struct import \* import sys, socket def int2ip(addr): return socket.inet\_ntoa(pack("!I", addr)) config\_file = sys.argv\[1\] f = open(config\_file, 'rb') fd = f.read() f.close() decrypted = "" for x in fd\[32:\]: decrypted += chr(ord(x) ^ 0x5f) port = unpack("\<I", decrypted\[4:8\])\[0\] ip = int2ip(unpack("\>I", decrypted\[8:12\])\[0\]) print "IP Address : %s" % ip print "Port : %d" % port

|----------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 | from struct import \* import sys, socket def int2ip(addr): return socket.inet\_ntoa(pack("!I", addr)) config\_file = sys.argv\[1\] f = open(config\_file, 'rb') fd = f.read() f.close() decrypted = "" for x in fd\[32:\]: decrypted += chr(ord(x) ^ 0x5f) port = unpack("\<I", decrypted\[4:8\])\[0\] ip = int2ip(unpack("\>I", decrypted\[8:12\])\[0\]) print "IP Address : %s" % ip print "Port : %d" % port |

The malware will then read in and parse the included plugin configuration information, which is found within the glp.uin file that was previously dropped. These included plugins are encrypted and compressed using the same method witnessed by the hjwe.dat file previously. The previously included script can be used to decrypt and decompress the following three plugin files:

* tyeu.dat
* vnkd.dat
* qhnj.dat

These three plugins are subsequently loaded after being decrypted and decompressed. An overview of these plugins can be found later in this post.

The malware proceeds to create the following event:

*Global\\\\{34748A26-4EAD-4331-B039-673612E8A5FC}*

Additionally, the following three mutexes are created:

*Global\\\\{3C6FB3CA-69B1-454f-8B2F-BD157762810E}* *Global\\\\{43EE34A9-9063-4d2c-AACD-F5C62B849089}* *Global\\\\{A8859547-C62D-4e8b-A82D-BE1479C684C9}*

The malware will spawn a new thread to handle network communication. The following event is created prior to this communication occurring:

*Global\\\\{EED5CA6C-9958-4611-B7A7-1238F2E1B17E}*

The malware includes proxy support in the event that the victim is behind a web proxy. Network traffic occurs over a binary protocol on the port specified within the configuration. Traffic is xor-encrypted with a single-byte key of 0x55 in an attempt to bypass any network security products that may be in place. Once decrypted, the following traffic is sent by the malware.

[![T9000 4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-4-500x275.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-4.png)

Figure 1: Decrypted data sent by malware

As we can see from the above image, the malware will send out an initial beacon, followed by various collected information from the victim machine. The following information is exfiltrated:

* Installed security products
* System time
* Build Number
* CPU Architecture (32-bit/64-bit)
* MAC Address
* IP Address
* Hostname
* Username
* Parent executable name
* Plugin configuration information

The malware is configured to receive a number of commands. The following command functionalities have been identified.

|-------------|-----------------------------------------------|
| **Command** | **Description**                               |
| DIR         | Directory listing                             |
| LIR         | Drive listing                                 |
| RUN         | Execute command (Either interactively or not) |
| CIT         | Send command to interactively spawned command |
| CFI         | Kill interactively spawned process            |
| DOW         | Download file                                 |
| UPL         | Upload file                                   |
| DEL         | Delete file                                   |
| DTK         | Retrieve statistics for file                  |
| ERR         | Null command                                  |

Additionally, the following commands have been identified, however, their functionalities have yet to be fully discovered.

* PNG
* PLI
* PLD
* FDL
* OSC
* OSF
* SDA
* QDA
* TFD
* SDS
* SCP
* FMT
* STK
* CRP

#### Plugin \#1 -- tyeu.dat

When this plugin is called with the default exported function, it will create the following mutex:

*{CE2100CF-3418-4f9a-9D5D-CC7B58C5AC62}*

When called with the SetCallbackInterface function export, the malicious capabilities of the plugin begin. The plugin begins by collecting the username of the running process, and determining if it is running under the SYSTEM account. If running as SYSTEM, the plugin will associate the active desktop with the plugin's thread.

The plugin proceeds to create the following named event:

*Global\\\\{EED5CA6C-9958-4611-B7A7-1238F2E1B17E}*

Multiple threads are then spawned to handle various actions. The first thread is responsible for taking a screenshot of the desktop of the victim machine. This screenshot data is both compressed and encrypted using a single-byte xor key of 0x5F. This data is written to one of the following files:

*%PUBLIC%\\Downloads\\Update\\S\[random\].dat* *%ALLUSERSPROFILE%\\Documents\\My Document\\S\[random\].dat*

The random data is generated via the current system time. Additionally, when a screenshot is written, one of the following log files has data appended to it:

*%PUBLIC%\\Downloads\\Update\\Log.txt* *%ALLUSERSPROFILE%\\Documents\\My Document\\Log.txt*

[![T9000 5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-5-500x148.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-5.png)

Figure 2: Example data found within Log.txt file

A second thread is responsible for monitoring the foreground window every 20 seconds. The thread will target the window names set within the plugin configuration. In this particular instance, the malware will target the 'notepad' process.

When this process is discovered to be running in the foreground window, the malware will take a screenshot of this window. The data is compressed and encrypted using a single-byte xor key of 0x5F. This data is written to one of the following files:

*%PUBLIC%\\Downloads\\Update\\W\[random\].dat* *%ALLUSERSPROFILE%\\Documents\\My Document\\W\[random\].dat*

Like the previous thread, this one attempts to write another log file to the disk. However, due to a bug within the code of this plugin, the malware author attempts to append the 'C:\\\\Windows\\\\Temp\\\\Log.txt' string to the path, resulting in an inaccessible file path. In the event this bug did not exist, the following example data would be written:

*08:37:49 2000 \[4\] PrintKeyTitleWnd: ===\>\> Process ID : 2000*

The third and final thread spawned by this plugin is responsible for collecting information from the Skype program. The malware will use the built-in Skype API to accomplish this. This only takes places if both Skype is running and the victim is logged into Skype. It makes calls to the following functions:

* SkypeControlAPIDiscover
* SkypeControlAPIAttach

When hooking into the Skype API, the victim is presented with the following dialog:

[![T9000 6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-6-500x44.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-6.png)

Figure 3: Skype API access request

The victim must explicitly allow the malware to access Skype for this particular functionality to work. However, since a legitimate process is requesting access, the user may find him- or herself allowing this access without realizing what is actually happening.

Once enabled, the malware will record video calls, audio calls, and chat messages. Audio and video files are stored in the following folder:

*%APPDATA%\\Intel\\Skype*

Temporary audio and video files are stored within the audio and video sub-folders respectively. After a call is finished, this data is compressed and encrypted using the same techniques previously witnessed. These files are stored in randomly named .dat files within the Skype folder.

[![T9000 7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-7-500x223.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-7.png)

When decrypted, we can see that the malware periodically takes images of the video calls. Audio calls are stored as .wav files.

[![T9000 8](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-8-500x319.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-8.png)

Figure 4: A lonely malware reverser is captured on video by the malicious plugin

The original name for this plugin is 'CaptureDLL.dll'. This is aptly named, as we see that this plugin has the following functionality:

* Capture full desktop screenshots
* Capture window screenshots of targeted processes
* Capture Skype audio, video, and chat messages

#### Plugin \#2 -- vnkd.dat

The vnkd.dat plugin has the following debug path, leading us to believe that the original name for this plugin is 'FlashDiskThief':

*e:\\WORK\\Project\\T9000\\Windows\\Target\\FlashDiskThief.pdb*

When loaded with the default DllEntryPoint exported function, it will create the following mutex:

*Global\\\\{6BB1120C-16E9-4c91-96D5-04B42D1611B4}*

Like the other plugins associated with this malware, the majority of the functionality for this malware resides within the SetCallbackInterface exported function. This function spawns a new thread that begins by registering a new window with a class name and window name of 'xx'.

The plugin proceeds to iterate through all connected drives on the system, looking for removable drives.

[![T9000 9](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-9-500x122.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-9.png)

Figure 5. Plugin check for removable drives

Should a removable drive be discovered, the plugin will seek any files residing on this device based on the plugin's configured list. In this particular instance, the malware will seek out the following file types:

* \*.doc
* \*.ppt
* \*.xls
* \*.docx
* \*.pptx
* \*.xlsx

If one of these file types is found, the malware will create a copy of the file in one of the following paths:

*%PUBLIC%\\Downloads\\Update\\D\[random\].tmp
%ALLUSERSPROFILE%\\Documents\\My Document\\D\[random\].tmp*

The data found within this file is encrypted using a single-byte xor key of 0x41. The file header structure, with the underlying data still encrypted, can be seen below.

[![T9000 10](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-10-500x217.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-10.png)

Figure 6: File structure prior to decryption

[![T9000 11](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-11-500x186.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/T9000-11.png)

Figure 7: File structure post decryption

This concludes the functionality of the vnkd.dat plugin, or FlaskDiskThief as it's known by the malware's author. While specific in nature, this plugin allows attackers to collect files being passed around from one machine to another via removable drives.

#### Plugin \#3 -- qhnj.dat

This particular plugin appears to have an original filename of 'kplugin.dll' due to debugging information found within the file. The qhnj.dat plugin is responsible for hooking a number of common Microsoft Windows API calls, and logging the results.

The following functions are hooked by this plugin:

* ImmGetCompositionStringA
* ImmGetCompositionStringW
* CreateFileW
* DeleteFileW
* CopyFileExW
* MoveFileWithProgressW
* CreateDirectoryW
* CreateDirectoryExW
* RemoveDirectoryW
* GetClipboardData
* CryptEncrypt
* CryptDecrypt

The plugin is most likely hooking the ImmGetCompositionString\* functions in order to collect information about Unicode characters on the victim machine, such as Chinese, Japanese, and Korean.

Hooking the various file and directory operations allows the malware to log what file changes are occurring on the system. When a file is created, copied, moved, or deleted on the system, the malware will check the directory of said file against the following blacklist:

* \\\\\\\\.\\\\
* :\\\\program files\\\\
* \\\\AppData\\\\
* \\\\temporary internet files\\\\
* \\\\application data\\\\
* \\\\Local Settings\\\\
* \\\\cookies\\\\
* \\\\temp\\\\
* \\\\history\\\\

Additionally, the filename is compared against the '.tmp' extension to ensure a temporary file is ignored.

Should the file meet the required criteria, this data is logged. Additionally, all folder modifications and clipboard data are logged as well.

The Crypt\* functions allow the malware to collect sensitive encrypted data sent to and from the victim machine. This is especially useful when viewing network traffic, allowing the attackers to potentially gain access to remote systems used by the victim.

All of the data logged by the qhnj.dat plugin file is stored in one of the following file paths. Data is encrypted using a single-byte XOR key of 0x79.

*%PUBLIC%\\Downloads\\Update\\uai\[random\].tmp* *%ALLUSERSPROFILE%\\Documents\\My Document\\uai\[random\].tmp*

This last plugin allows the attackers to record important actions taken by the victim, which in turn may allow them to gain additional access as well as insight into the victim's actions.

### Conclusion

T9000 appears to be the latest version of this Trojan, which has been partially exposed in previous reports. In 2013, Cylance published a report on a group they named "[Grand Theft Auto Panda](https://blog.cylance.com/grand-theft-auto-panda)", which includes some details on the T5000 version of this Trojan. [FireEye researchers](https://www.fireeye.com/blog/threat-research/2014/03/spear-phishing-the-news-cycle-apt-actors-leverage-interest-in-the-disappearance-of-malaysian-flight-mh-370.html) also noted that the malware was used in an attack in 2014 using a lure related to the disappearance of Malaysian flight MH370.

The author of this backdoor has gone to great lengths to avoid being detected and to evade the scrutiny of the malware analysis community. We hope that sharing the details of how this tool works as well as the indicators in the section below will help others defend themselves against attacks using this tool.

In a future report, we will detail the infrastructure used by the variants of the malware we have identified and discuss the methods attackers use to infect systems with it.

Palo Alto Networks customers are protected from T9000/T5000 attacks through our next-generation security platform, including the following.

* **Threat Prevention** signatures for the software vulnerabilities listed in this report are available to detect the exploit files during delivery.
* **Traps** is capable of preventing exploitation of the vulnerabilities exploited to install T9000.
* **WildFire** classifies all of the malware described in this report as malicious.
* **Anti-malware signatures** for the files listed in this report.
* **AutoFocus** users can identify the malware discussed in this report with the [T5000 tag](https://autofocus.paloaltonetworks.com/#/tag/Unit42.T5000)

### Indicators of Compromise

**Hashes**

RTF File, d5fa43be20aa94baf1737289c5034e2235f1393890fb6f4e8d4104565be52d8c  
QQMGr.dll, bf1b00b7430899d33795ef3405142e880ef8dcbda8aab0b19d80875a14ed852f  
QQMGR.inf, ace7e3535f2f1fe32e693920a9f411eea21682c87a8e6661d3b67330cd221a2a  
ResN32.dat, aa28db689f73d77babd1c763c53b3e63950f6a15b7c1a974c7481a216dda9afd  
ResN32.dll, 1cea4e49bd785378d8beb863bb8eb662042dffd18c85b8c14c74a0367071d9a7  
hqwe.dat, bb73261072d2ef220b8f87c6bb7488ad2da736790898d61f33a5fb7747abf48b  
hqwe.dat.decrypted, 7daf3c3dbecb60bee3d5eb3320b20f2648cf26bd9203564ce162c97dcb132569  
hccutils.dll, 3dfc94605daf51ebd7bbccbb3a9049999f8d555db0999a6a7e6265a7e458cab9  
hccutils.inf, f05cd0353817bf6c2cab396181464c31c352d6dea07e2d688def261dd6542b27  
igfxtray.exe, 21a5818822a0b2d52a068d1e3339ed4c767f4d83b081bf17b837e9b6e112ee61  
qhnj.dat, c61dbc7b51caab1d0353cbba9a8f51f65ef167459277c1c16f15eb6c7025cfe3  
qhnj.dat.decrypted, 2b973adbb2addf62cf36cef9975cb0193a7ff0b960e2cff2c80560126bee6f37  
tyeu.dat, e52b5ed63719a2798314a9c49c42c0ed4eb22a1ac4a2ad30e8bfc899edcea926  
tyeu.dat.decrypted, 5fc3dc25276b01d6cb2fb821b83aa596f1d64ae8430c5576b953e3220a01d9aa  
vnkd.dat, c22b40db7f9f8ebdbde4e5fc3a44e15449f75c40830c88932f9abd541cc78465  
vnkd.dat.decrypted, 157e0a9323eaaa911b3847d64ca0d08be8cd26b2573687be461627e410cb1b3f  
dtl.dat, 00add5c817f89b9ec490885be39398f878fa64a5c3564eaca679226cf73d929e  
glp.uin, 3fa05f2f73a0c44a5f51f28319c4dc5b8198fb25e1cfcbea5327c9f1b3a871d4

**Mutexes**

820C90CxxA1B084495866C6D95B2595xx1C3  
Global\\\\deletethread  
Global\\\\{A59CF429-D0DD-4207-88A1-04090680F714}  
Global\\\\{3C6FB3CA-69B1-454f-8B2F-BD157762810E}  
Global\\\\{43EE34A9-9063-4d2c-AACD-F5C62B849089}  
Global\\\\{A8859547-C62D-4e8b-A82D-BE1479C684C9}  
{CE2100CF-3418-4f9a-9D5D-CC7B58C5AC62}  
Global\\\\{6BB1120C-16E9-4c91-96D5-04B42D1611B4}

**Named Events**

Global\\\\{34748A26-4EAD-4331-B039-673612E8A5FC}  
Global\\\\{EED5CA6C-9958-4611-B7A7-1238F2E1B17E}

**File Modifications**

%TEMP%\\~tmp.doc  
%APPDATA%\\Intel\\avinfo  
%APPDATA%\\Intel\\Data\\dtl.dat  
%APPDATA%\\Intel\\Data\\glp.uin  
%APPDATA%\\Intel\\Data\\  
%APPDATA%\\Intel\\~1  
%APPDATA%\\Intel\\hccutils.dll  
%APPDATA%\\Intel\\hccutils.inf  
%APPDATA%\\Intel\\hjwe.dat  
%APPDATA%\\Intel\\igfxtray.exe  
%APPDATA%\\Intel\\qhnj.dat  
%APPDATA%\\Intel\\QQMgr.dll  
%APPDATA%\\Intel\\QQMgr.inf  
%APPDATA%\\Intel\\ResN32.dll  
%APPDATA%\\Intel\\ResN32.dat  
%APPDATA%\\Intel\\tyeu.dat  
%APPDATA%\\Intel\\vnkd.dat  
%STARTUP%\\hccutils.dll  
%STARTUP%\\hccutil.dll  
%STARTUP%\\igfxtray.exe  
%ALLUSERSPROFILE%\\Documents\\My Document\\utd\_CE31  
%ALLUSERSPROFILE%\\Documents\\My Document\\XOLOADER  
%ALLUSERSPROFILE%\\Documents\\My Document\\update  
%ALLUSERSPROFILE%\\Documents\\My Document\\Log.txt  
%PUBLIC%\\Downloads\\Update\\utd\_CE31  
%PUBLIC%\\Downloads\\Update\\XOLOADER  
%PUBLIC%\\Downloads\\Update\\update  
%PUBLIC%\\Downloads\\Update\\Log.txt  
%APPDATA%\\Intel\\Skype

**Registry Modifications**

HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Eupdate - %APPDATA%\\Intel\\ResN32.dll  
HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\update - %SYSTEM%\\rundll32.exe %APPDATA\\Intel\\ResN32.dll Run  
HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\AppInit\_DLLs - %APPDATA%\\Intel\\ResN32.dll  
HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\LoadAppInit\_DLLs -- 0x1  
HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\update -- c:\\windows\\system32\\rundll32.exe %APPDATA\\Intel\\ResN32.dll Run

**Command and Control**

198\.55.120\[.\]143:8080
Back to top

### Tags

* [Skype](https://unit42.paloaltonetworks.com/tag/skype/ "Skype")
* [T5000](https://unit42.paloaltonetworks.com/tag/t5000/ "T5000")
* [T9000](https://unit42.paloaltonetworks.com/tag/t9000/ "T9000")
* [Trojans](https://unit42.paloaltonetworks.com/tag/trojans/ "Trojans")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?](https://unit42.paloaltonetworks.com/emissary-trojan-changelog-did-operation-lotus-blossom-cause-it-to-evolve/ "Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?")

### Related Articles

* [Kazuar: Multiplatform Espionage Backdoor with API Access](https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/ "article - table of contents")
* [Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?](https://unit42.paloaltonetworks.com/emissary-trojan-changelog-did-operation-lotus-blossom-cause-it-to-evolve/ "article - table of contents")
* [Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists](https://unit42.paloaltonetworks.com/scarlet-mimic-years-long-espionage-targets-minority-activists/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
