HyperBro is a Windows in-memory remote access trojan and backdoor associated primarily with the China-linked APT27 intrusion set, also tracked as LuckyMouse, Emissary Panda, Iron Tiger, and BRONZE UNION. It provides persistent remote access, command execution, file and service management, screen capture, and data exfiltration. HyperBro has been deployed through DLL side-loading, in which a legitimate executable loads a malicious DLL that decrypts, decompresses, and executes the payload in memory. Observed variants can inject shellcode into newly created processes and delete specified files, supporting stealth and artifact cleanup. APT27 has used HyperBro in cyber-espionage operations against government and commercial entities, including organizations in Europe, the Middle East, and Mongolia. Delivery has also occurred through trojanized installers and compromised update mechanisms for legitimate chat software. HyperBro has been used following exploitation of public-facing enterprise applications to establish durable access and support collection of sensitive business, government, and research data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
their report notes the attacks are representative of an increase in the use of HyperBro malware by Chinese threat groups against German targets ... APT27’s operation ... ultimately deploying HyperBro malware to exfiltrate many gigabytes of data
DEVCORE Team discovered both CVE-2021-26855 and CVE-2021-27065. The exploitation of these two vulnerabilities leads to remote code execution with SYSTEM permissions, allowing attackers to drop webshells, for instance.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Initial access was believed to be via CVE-2019-0604, after which the actors planted multiple web shells... In April 2019 to deploy web shells on government-related SharePoint servers in the Middle East.
In March 2021, APT27 exploited Microsoft Exchange Server ProxyLogon vulnerabilities (CVE-2021-26855/-26857/-26858/-27065) affecting Microsoft Exchange Server 2013, 2016, and 2019. The group leveraged the exploit chain to gain pre-authentication remote code execution and deploy HyperBro backdoor. | HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
In March 2021, APT27 exploited Microsoft Exchange Server ProxyLogon vulnerabilities (CVE-2021-26855/-26857/-26858/-27065) affecting Microsoft Exchange Server 2013, 2016, and 2019. The group leveraged the exploit chain to gain pre-authentication remote code execution and deploy HyperBro backdoor. | HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
Although LuckyMouse has been spotted using a widely used Microsoft Office vulnerability (CVE-2017-11882) to weaponize Office documents in the past, researchers have no proofs of this technique being used in this particular attack against the data center.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition, the group is also known to rely on the HyperBRO malware, a Remote Access Trojan (RAT).
HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
ESET researchers discovered that chat software called Able Desktop ... was used to deliver the HyperBro backdoor (commonly used by LuckyMouse) ... In mid-2018, we observed a first occurrence of the legitimate Able Desktop application being used to download and execute HyperBro.
UNC215 often uses FOCUSFJORD for the initial stages of an intrusion, and then later deploys HYPERBRO, which has more information collection capabilities such as screen capture and keylogging.
The same benign vfhost.exe file has also been abused in activity we attribute to... TAG-67 ... to load HyperBro through a similar low-prevalence DLL search order hijacking triad.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The first activity discovered was the exploitation of a Microsoft Exchange server using ProxyLogon vulnerabilities chain... On March, 4th of 2021, APT27 exploited ProxyLogon vulnerabilities chain affecting Microsoft Exchange server to gain initial access.
In order to execute remote command, threat actors also relied on valid credentials collected in previous stages used wmic tool to execute commands on remote hosts.
Execution T1059.001 Command and Scripting Interpreter: PowerShell ... cmd.exe /Q /c powershell Add-MpPreference -ExclusionPath C:\Windows\temp
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell ... Adversaries were wrapping their commands through calls to cmd.exe /Q /c command line.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
The pattern of compromise is to use several different means to gain access to systems [5, 6], followed by the installation of HyperBro (and/or the HyperSSL variant).
The loader will then use the process hollowing technique to inject HyperBro backdoor (Stage 3).
In some cases the attackers modified a clean installer in about 90 minutes, inserting obfuscated JavaScript into electron-main.js.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Defense Evasion T1036.004 Masquerading: Masquerade Task or Service
Defense Evasion T1036.005 Masquerading: Match Legitimate Name or Location ... rename it to veeamGues.exe to hide it in plain sight.
The loader will then use the process hollowing technique to inject HyperBro backdoor (Stage 3).
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The defendants ... conducted unauthorized intrusions into victim networks by exploiting software vulnerabilities, conducting internal reconnaissance, and deploying malware such as PlugX to establish persistent access. The indictment alleges that the group stole data from compromised networks and transferred it to servers under their control.
The group has also used backdoors with keylogging functionality, to passively capture user credentials over time.
URLs time.ntp-server.asia C&C 45.142.214.193 C&C linux.updatelive-oline.com C&C center.veryssl.org C&C https://139.180.216.65:443/api/v2/ajax C&C
The article identifies “an actual C2 that belongs to APT27” by searching for URLs containing the “/api/v2/ajax” URI sequence. It also describes HyperBro C2 servers responding on TCP port 443 with HTTP 500 errors.
Starting closest to the actors, we see connections from Chinanet Backbone or Alibaba establishing tunnels to the management VPN nodes at DigitalOcean. From these, they create tunnels to operational nodes, which they use to SSH into the malware controllers.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family referenced as one of several shared tools appearing across multiple Chinese APT campaigns.
Malware associated in the content with APT27/Iron Tiger. Its C2 servers are described as commonly returning HTTP 500 Internal Server Error responses with zero content on TCP/443, enabling infrastructure hunting through matching Shodan response hashes.
HyperBro is a remote access trojan used in targeted attacks, often associated with espionage operations.
Custom in-memory backdoor/RAT used by APT27 for persistent access, command execution, credential theft support, screenshots, file and service management, shellcode injection, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.