Briba is a Windows malware family associated with Chinese espionage activity, including operations linked to the Sunshop intrusion cluster and the broader Sunshop Digital Quartermaster ecosystem. It has been observed alongside other APT tooling such as Poison Ivy and 9002 RAT in targeted campaigns against organizations in sectors including government, telecommunications, finance, and high technology.
Briba is used as a DLL-based backdoor or remote-access implant. It has been documented executing through rundll32.exe, including via Registry Run keys and Startup folder persistence, allowing the malware to survive reboots and user logons while blending execution with a trusted Windows binary. It has also been observed installing a Windows service that points to a malicious DLL, providing an additional persistence mechanism. Briba can download files onto infected hosts, indicating support for follow-on payload delivery and post-compromise tasking.
Campaign reporting ties Briba to strategic web compromise activity and exploit-driven delivery. In Sunshop-related operations, victims were redirected from compromised websites to exploit infrastructure using browser and Java vulnerabilities, after which implants including Briba were deployed. Related activity also involved zero-day exploitation and watering-hole style targeting of high-value organizations and communities. Overall, Briba fits the pattern of an espionage-oriented Windows backdoor used for persistent access, stealthy DLL execution, and retrieval of additional tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After further research into 58.64.205.53 with our friends at Mandiant we uncovered a Briba sample with the MD5 6fe0f6e68cd9cc6ed7e100e7b3626665 that connected to this IP address.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that establishes persistence through Run key entries referencing dropped malicious DLLs.
Backdoor malware that persists through Registry Run entries pointing to dropped DLLs.
Backdoor that uses rundll32.exe for persistence and DLL execution.
Backdoor that persists by installing a service referencing a malicious DLL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.