ELMER is a Delphi-based Windows backdoor associated with the Chinese espionage group APT16. It has been used in intrusions targeting organizations in Japan and Taiwan, including entities in the high-technology, government, media, and financial sectors. The malware is designed for remote command execution and data theft, and communicates with its command-and-control infrastructure over HTTP, including traffic sent over TCP port 443 to blend with common web activity.
ELMER employs multiple implementation features intended to hinder analysis and improve operational reliability. Reported samples use custom code and string encryption routines, decrypt strings at runtime, and dynamically resolve Windows API functions. The malware also inspects local proxy settings before establishing outbound communications, gathers basic host identification data such as hostname and local IP address, and transmits that information during initial beaconing.
The backdoor supports a compact but capable command set for post-compromise operations. Documented functions include file upload and download, execution of commands or processes, enumeration of files and directories, exfiltration of file contents, reporting of the current directory, and process discovery. Its process-listing capability uses standard Windows snapshot APIs to enumerate running processes and return process names and identifiers to the operator. These features make ELMER suitable for reconnaissance, remote tasking, and follow-on collection within targeted espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2015-2545 is a vulnerability discovered in 2015 and corrected with Microsoft’s update MS15-099... enables an attacker to execute arbitrary code using a specially crafted EPS image file... exploited in the wild in August 2015... used in targeted attack by the Platinum group.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this blog post, we’re presenting a detailed analysis of a backdoor known as ELMER that was used by the Chinese actor identified as APT16.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware opens the “Software\Microsoft\Windows\CurrentVersion\Internet Settings” registry key by calling the RegOpenKeyExA API... The “ProxyEnable” value is extracted using the RegQueryValueExA function.
If “ProxyEnable” is equal to 1, the malware proceeds and extracts the value of “ProxyServer” (hostnames/IPs of the proxy server on the network).
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The gethostname function is used to retrieve the host name for the local machine... The inet_ntoa function is utilized to convert the IP address of the host into an ASCII string... The hostname and the IP address of the machine... are combined into a string that will be used in the upcoming network communications with the C2 server.
The process constructs the next buffer for every file: 1|File name|dwHighDateTime (high-order 32 bits of the file time) in decimal|File size in decimal|. | The malware scans the current directory using the FindFirstFileA and FindNextFileA functions... The current directory name is sent to the CnC server in the following form “7|1|Directory name|”.
Data exfiltration is performed using an HTML document that contains the information encoded using the NOT operator.
The sample performs a GET request to the C2 server with the user agent that was decrypted earlier... The malware reads the response from the server using the recv function... it checks to see if the response contains “200 OK”... The hostname and the IP address of the local machine are exfiltrated to the C2 server using a POST request. | The sample performs a GET request to the C2 server with the user agent that was decrypted earlier: “User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1)”... The hostname and the IP address of the local machine are exfiltrated to the C2 server using a POST request.
The hostname and the IP address of the local machine are exfiltrated to the C2 server using a POST request... The list of processes is exfiltrated to the CnC server... The content of the targeted file is exfiltrated to the CnC server using the send function.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware capable of performing process listings.
Delphi-based backdoor used by APT16 that decrypts strings and code with custom algorithms, detects proxy settings, collects host and IP information, communicates with a C2 over HTTP, and supports eight commands including file upload/download, process execution, file and directory enumeration, process listing, and file-content exfiltration. The sample also appears capable of downloading additional payloads.
Backdoor referenced as used by APT16 in Taiwan via CVE-2015-2545 exploit documents.
Backdoor with process listing capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.