AIRBREAK, also referred to as Orz, is a custom JavaScript backdoor associated with the China-linked espionage actor APT40, also tracked as Leviathan, MUDCARP, and temp.Periscope. It has been described as a first-stage backdoor used before downloading additional payloads. Reported delivery includes spearphishing campaigns using malicious attachments and URLs, including Office documents exploiting CVE-2017-0199 and CVE-2017-8759, as well as socially engineered Publisher files. In one reported chain, a Windows executable spoofing a decryption tool dropped the Orz JavaScript backdoor and executed it via Wscript. Related tooling used alongside AIRBREAK/Orz includes NanHaiShu, SeDll, MockDll, Cobalt Strike, GreenCrash, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit/Meterpreter, ScanBox, and Derusbi.
Observed capabilities include registry operations and overwriting registry settings to reduce visibility, execution of shell commands and JavaScript commands, gathering the victim’s Internet Explorer version, proxy information, and process lists, as well as file upload/download, drive enumeration, process management, and HTTP GET/POST communications. AIRBREAK/Orz has used Technet and Pastebin pages, attacker-controlled servers, and compromised victim web servers for command and control; one older variant reportedly used vitaminmain[.]info as a secondary C2 server. Some versions contain an embedded DLL called MockDll that uses process hollowing and regsvr32 to execute another payload. SeDll has also been used to decrypt and execute JavaScript backdoors such as Orz.
The malware has been linked to long-running espionage activity targeting defense contractors, government agencies, universities with military ties, legal organizations, and maritime-related entities, particularly in the United States, Western Europe, and South China Sea-related contexts. High-confidence indicators and artifacts directly mentioned in the content include the domains chemscalere[.]com, candlelightparty[.]org, www.candlelightparty[.]org, newapp.freshasianews[.]com, and vitaminmain[.]info; the FTP/HTTP infrastructure 185.106.120[.]206 used in one infection chain; and persistence via a Run key at HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run with the value help='c:\windows\system32\rundll32.exe c:\windows\system32\zipfldr.dll,RouteTheCall c:\programdata\winapp.exe'. Additional reported persistence artifacts include Startup shortcuts named "Java(TM) Platform SE Auto Updater.lnk" and "office 365.lnk".
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tools Nanhaishu, Orz, SeDll, Cobalt Strike, GreenCrash, AIRBREAK, BlackCoffee, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit / Meterpreter, ScanBox, Derusbi Trojan, Derusbi, Metasploit
24 distinct techniques documented for this family, organized by ATT&CK tactic.
This definition in turn downloads a VBScript favicon.ico file, which then creates and runs two JavaScript files in the %TMP% directory.
The actor continues to: Use scripting languages such as JavaScript, JavaScript Scriptlets, VBScript, and XML
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Use simple obfuscation such as base64, gzip compression, and insertion of garbage characters
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
"Bundlore has the ability to enumerate what browser is being used as well as version information"; "Orz can gather the victim's Internet Explorer version"; "SUGARDUMP can identify ... browsers, including version number"; "SideCopy has collected browser information"
"Bazar can query the Registry for installed applications." / "BRONZE BUTLER has used tools to enumerate software installed on an infected host." / "LightSpy ... enumerate the Applications folder to collect the bundle name, bundle identifier, and version information..." / "Volt Typhoon has queried the Registry on compromised systems for information on installed software."
Its functionality includes: GET request to a URL POST request to a URL
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware with an embedded DLL, MockDll, that uses Process Hollowing and regsvr32 to execute another payload.
A custom-built JavaScript backdoor associated with MUDCARP that is dropped by a Windows executable and executed using Wscript, with persistence established via rundll32 and zipfldr.dll RouteTheCall after reboot.
Backdoor that uses public web pages (TechNet, Pastebin) for command-and-control.
Malware that uses TechNet and Pastebin web pages for command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.